{"id":13721,"date":"2025-07-21T20:23:07","date_gmt":"2025-07-21T20:23:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/13721\/"},"modified":"2025-07-21T20:23:07","modified_gmt":"2025-07-21T20:23:07","slug":"sharepoint-vulnerability-with-9-8-severity-rating-under-exploit-across-globe","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/13721\/","title":{"rendered":"SharePoint vulnerability with 9.8 severity rating under exploit across globe"},"content":{"rendered":"<p>Installing the updates is only the beginning of the recovery process, since the infections are allowing attackers to make off with authentication credentials that give wide access to a variety of sensitive resources inside a compromised network. More about those additional steps later in this article.<\/p>\n<p>On Saturday, researchers from security firm Eye Security <a href=\"https:\/\/research.eye.security\/sharepoint-under-siege\/\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> finding \u201cdozens of systems actively compromised during two waves of attack, on 18th of July around 18:00 UTC and 19th of July around 07:30 UTC.\u201d The systems, scattered across the globe, had been hacked using the exploited vulnerability and then infected with a webshell-based backdoor called ToolShell. Eye Security researchers said that the backdoor was able to gain access to the most sensitive parts of a SharePoint Server and from there extract tokens that allowed them to execute code that let the attackers to expand their reach inside networks.<\/p>\n<p>\u201cThis wasn\u2019t your typical webshell,\u201d Eye Security researchers wrote. \u201cThere were no interactive commands, reverse shells, or command-and-control logic. Instead, the page invoked internal .NET methods to read the SharePoint server\u2019s MachineKey configuration, including the ValidationKey. These keys are essential for generating valid __VIEWSTATE payloads, and gaining access to them effectively turns any authenticated SharePoint request into a remote code execution opportunity.\u201d<\/p>\n<p>The remote code execution is made possible by using the exploit to target the way SharePoint translates data structures and object states into formats that can be stored or transmitted and then reconstructed later, a process known as <a href=\"https:\/\/en.wikipedia.org\/wiki\/Serialization\" rel=\"nofollow noopener\" target=\"_blank\">serialization<\/a>. A <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2021\/7\/7\/cve-2021-28474-sharepoint-remote-code-execution-via-server-side-control-interpretation-conflict\" rel=\"nofollow noopener\" target=\"_blank\">SharePoint vulnerability<\/a> Microsoft fixed in 2021 had made it possible to abuse parsing logic to inject objects into pages. This occurred because SharePoint ran ASP.NET ViewState objects using the ValidationKey signing key, which is stored in the machine\u2019s configuration. This could enable attackers to cause SharePoint to deserialize arbitrary objects and execute embedded commands. Those exploits, however, were limited by the requirement to generate a valid signature, which in turn required access to the server\u2019s secret ValidationKey.<\/p>\n","protected":false},"excerpt":{"rendered":"Installing the updates is only the beginning of the recovery process, since the infections are allowing attackers to&hellip;\n","protected":false},"author":2,"featured_media":13722,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[43,44,41,39,42,40],"class_list":["post-13721","post","type-post","status-publish","format-standard","has-post-thumbnail","category-headlines","tag-headlines","tag-news","tag-top-news","tag-top-stories","tag-topnews","tag-topstories"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/13721","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=13721"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/13721\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/13722"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=13721"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=13721"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=13721"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}