Vietnam.vn - Nền tảng quảng bá Việt Nam

Bkav Technology Group warns of cyber attack risks from a series of vulnerabilities in Microsoft's SharePoint Server software

Bkav Technology Group said that there are currently 4 serious zero-day vulnerabilities existing on SharePoint Server 2016, 2019 and Subscription Edition versions, allowing hackers to remotely take control of the system without authentication.

Báo Sài Gòn Giải phóngBáo Sài Gòn Giải phóng26/07/2025

SharePoint Server is an enterprise collaboration and document management platform developed by Microsoft.
SharePoint Server is an enterprise collaboration and document management platform developed by Microsoft.

In particular, when exploiting two of these vulnerabilities together, hackers can gain deep control over the system and maintain long-term access. This is an "ideal environment" for APT (Advanced Persistent Threat) espionage campaigns, stealing or encrypting sensitive data.

These vulnerabilities are being exploited in a wide range of countries. At least 85 SharePoint servers have been infected with web shell malware, affecting 29 organizations globally. Among the victims are many multinational corporations and government agencies, including the US National Nuclear Security Administration (NNSA).

In Vietnam, SharePoint Server is used in document management at many agencies, organizations and large technology and financial enterprises. Up to now, although there have been no recorded cases of attacks, the risk of being exploited by these vulnerabilities is assessed at a very high level, especially at units that are deploying SharePoint Server according to the on-premise installation model without timely updating and patching.

The attack can originate from a point in the internal network, using sophisticated techniques that are difficult to detect. Hackers can secretly install malware on an internal workstation, from there silently scanning, expanding control and gradually taking over the entire system.

Bkav especially recommends that system administrators urgently review and tighten internal access rights to prevent the risk of attacks from within. For ministerial-level agencies that delegate access rights to local units, it is necessary to immediately review and limit these rights if the system has not been updated with patches or has not yet had a thorough solution. The update of vulnerability patches should be done as soon as possible.

At the same time, it is necessary to strengthen monitoring measures, limit external access, deploy web application firewalls (WAF), monitor system access logs and establish early warning mechanisms when there are signs of abnormalities. For units that do not have a specialized information security team, it is necessary to proactively contact incident response centers for timely advice and support...

SharePoint Server is a document management and enterprise collaboration platform developed by Microsoft. The system allows for centralized document storage, sharing, searching and management, and supports the construction of intranet websites, corporate portals, and deep integration with Microsoft Office and Microsoft 365 to improve team productivity.

Source: https://www.sggp.org.vn/tap-doan-cong-nghe-bkav-canh-bao-nguy-co-tan-cong-mang-tu-loat-lo-hong-tren-phan-mem-sharepoint-server-cua-microsoft-post805404.html


Comment (0)

No data
No data
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony
S-300PMU1 missiles on combat duty to protect Hanoi's sky
Lotus blooming season attracts tourists to the majestic mountains and rivers of Ninh Binh
Cu Lao Mai Nha: Where wildness, majesty and peace blend together
Hanoi is strange before storm Wipha makes landfall
Lost in the wild world at the bird garden in Ninh Binh
Pu Luong terraced fields in the pouring water season are breathtakingly beautiful
Asphalt carpets 'sprint' on North-South highway through Gia Lai
PIECES of HUE - Pieces of Hue
Magical scene on the 'upside down bowl' tea hill in Phu Tho

Heritage

Figure

Business

No videos available

News

Political System

Local

Product