CISA sounds alarm over trio of exploited SharePoint flaws
ID: d711dc4c-4029-5ecf-804c-cc72b294408c
STIX ID: report--d711dc4c-4029-5ecf-804c-cc72b294408c
Feed Name: The Register (Security)
CISA has warned organizations running supported on-premises SharePoint Server about multiple vulnerabilities—three already confirmed as actively exploited (including an RCE and privilege escalation) and two critical flaws labeled “Exploitation More Likely.” The advisory highlights post-exploitation techniques such as IIS machine key theft and deserialization used to gain persistence and deploy malware (including prior chaining to deploy Warlock ransomware), and recommends applying Microsoft patches, enabling AMSI integration, restricting external access to Central Administration, rotating IIS keys after threat hunting, and improving logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
