Critical 9.8 RCE vulnerability in Microsoft SharePoint Server. Actively exploited; immediate patching required for versions prior to 16.0.19725.20434.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| sharepoint_server | * | 16.0.19725.20434 | vulnerable |
| sharepoint_server | 2016 | 2016 | vulnerable |
| sharepoint_server | 2019 | 2019 | vulnerable |
Immediately download and install the security updates provided by Microsoft for SharePoint Server to address the underlying deserialization flaw.
Ensure all SharePoint Server instances are updated to version 16.0.19725.20434 or later, specifically targeting vulnerable SharePoint Server 2016 and 2019 deployments.
Minimize the attack surface by placing SharePoint servers behind a Web Application Firewall (WAF) and restricting management interface access to authorized internal IP addresses only.
Implement forensic triage requirements as per CISA BOD 26-04 and scan for indicators of compromise, such as unauthorized web shells or suspicious process execution.
"Monitor web server logs for anomalous POST requests targeting SharePoint service endpoints. Use EDR solutions to alert on suspicious child processes spawned by the SharePoint worker process (w3wp.exe), such as cmd.exe or powershell.exe. Additionally, deploy network-based signatures to detect common .NET deserialization gadgets and payloads within incoming traffic, and audit SharePoint ULS logs for serialization-related errors or unexpected type loading."
Experience superior visibility and a simpler approach to cyber risk management