Active SharePoint Exploits Highlight Patch & Hardening Failures
Threat actors are actively exploiting known vulnerabilities in on-premises SharePoint Server, leveraging unpatched systems to gain unauthorized access, execute remote code, and deploy malware. The root cause is a failure to apply available Microsoft patches in a timely manner, compounded by insufficient hardening of SharePoint deployments. Because these vulnerabilities are now listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, organizations running unpatched versions face a measurably elevated risk of compromise. This incident underscores that delayed patching of internet-facing collaboration platforms can have severe consequences, including data breaches and ransomware deployment.
Tactical Insight
Immediate Actions
- Apply all Microsoft SharePoint patches immediately, prioritizing vulnerabilities listed in CISA's KEV catalog.
- Enable AMSI (Antimalware Scan Interface) integration on SharePoint Server to detect and block malicious script execution.
- Audit all on-premises SharePoint instances to identify unpatched or end-of-life versions exposed to the internet.
Long-Term Improvements
- Establish a formal, risk-based patch management policy with defined SLAs for critical and actively exploited vulnerabilities.
- Maintain a complete and up-to-date inventory of all SharePoint deployments, including version and patch status.
- Evaluate migrating from on-premises SharePoint to cloud-hosted alternatives with vendor-managed patching where feasible.
Detection & Hardening Measures
- Implement continuous vulnerability scanning of internet-facing assets and integrate results with a SIEM for real-time alerting.
- Apply Microsoft's SharePoint hardening guidance, including least-privilege service accounts and disabling unnecessary features.
- Review SharePoint access logs and establish behavioral baselines to detect anomalous activity indicative of exploitation.