Vietnam.vn - Nền tảng quảng bá Việt Nam

Bkav Technology Group warns of cyber attack risks from a series of vulnerabilities in Microsoft's SharePoint Server software

Bkav Technology Group said that there are currently up to four serious zero-day vulnerabilities existing on SharePoint Server 2016, 2019 and Subscription Edition versions, allowing hackers to remotely take control of the system without authentication.

Báo Sài Gòn Giải phóngBáo Sài Gòn Giải phóng26/07/2025

SharePoint Server is an enterprise collaboration and document management platform developed by Microsoft.
SharePoint Server is an enterprise collaboration and document management platform developed by Microsoft.

In particular, when exploiting two of these vulnerabilities together, hackers can gain deep control over the system and maintain long-term access. This is an "ideal environment" for APT (Advanced Persistent Threat) espionage campaigns, stealing or encrypting sensitive data.

These vulnerabilities are being exploited widely in many countries. At least 85 SharePoint servers have been infected with web shell malware, affecting 29 organizations globally. Among the victims are many multinational corporations and government agencies, including the US National Nuclear Security Administration (NNSA).

In Vietnam, SharePoint Server is used in document management at many agencies, organizations and large technology and financial enterprises. Up to now, although no cases of attack have been recorded, the risk of being exploited by these vulnerabilities is assessed at a very high level, especially at units that are deploying SharePoint Server according to the on-premise installation model without timely updating and patching.

The attack can originate from a point in the internal network, using sophisticated techniques that are difficult to detect. Hackers can secretly install malware on an internal workstation, from there silently scanning, expanding control and gradually taking over the entire system.

Bkav especially recommends that system administrators urgently review and tighten internal access rights to prevent the risk of being attacked from within. For ministerial-level agencies that delegate access rights to local units, it is necessary to immediately review and limit these rights if the system has not been patched or has not been thoroughly remedied. Patching of vulnerabilities should be updated as soon as possible.

At the same time, it is necessary to strengthen monitoring measures, limit external access, deploy web application firewalls (WAF), monitor system access logs and set up early warning mechanisms when there are signs of abnormalities. For units that do not have a specialized information security team, it is necessary to proactively contact incident response centers for timely advice and support...

SharePoint Server is a document management and enterprise collaboration platform developed by Microsoft. The system allows storing, sharing, searching and managing documents centrally, and supports the construction of internal websites (Intranet), business portals, and deep integration with Microsoft Office and Microsoft 365 to improve team productivity.

Source: https://www.sggp.org.vn/tap-doan-cong-nghe-bkav-canh-bao-nguy-co-tan-cong-mang-tu-loat-lo-hong-tren-phan-mem-sharepoint-server-cua-microsoft-post805404.html


Comment (0)

No data
No data

Same tag

Same category

The beauty of Ha Long Bay has been recognized as a heritage site by UNESCO three times.
Lost in cloud hunting in Ta Xua
There is a hill of purple Sim flowers in the sky of Son La
Lantern - A Mid-Autumn Festival gift in memory

Same author

Heritage

;

Figure

;

Enterprise

;

No videos available

News

;

Political System

;

Destination

;

Product

;