Web_Logo
Remote Support
Microsoft Windows: Critical SharePoint Flaw Under Active Attack
Home » Security Alerts  »  Microsoft Windows: Critical SharePoint Flaw Under Active Attack

Microsoft Windows: Critical SharePoint Flaw Under Active Attack

A serious security flaw in Microsoft SharePoint Server is being actively exploited by attackers, and the US government's cyber security agency has confirmed real-world attacks are already underway.

  • What it is: Attackers who already have basic access to a SharePoint site can use this flaw to run their own code on the server, potentially taking full control.
  • Who is affected: On-premises SharePoint Server 2016, 2019, and Subscription Edition. Cloud-based SharePoint Online through Microsoft 365 is not affected.
  • What the risk is: Once exploited, an attacker could access confidential files, spread further into the network, or plant malware, without needing high-level permissions to begin with.
  • What action is needed: Businesses running SharePoint Server on their own hardware or in a private data centre should apply the latest security patch immediately.

We recommend any business running an on-premises SharePoint environment check with their IT provider today to confirm patching status. If you are unsure whether your systems are affected, get in touch and we can check for you.

Source: The Hacker News