Crypto Ticker:
sysadmin from Cyber Security News

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

Tushar Subhra Dutta
17 hours ago
9 Views
0 Comments
Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems. The attacks put on-premises SharePoint deployments at risk of data theft, network compromise, ransomware, and prolonged unauthorized access. The issue affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Attackers can chain authentication bypass, unsafe data processing, and input-validation flaws to turn an internet-facing collaboration server into an entry point for the wider corporate network. Researchers at Resecurity identified that the campaign can move quickly from a crafted web request to deeper...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!