SharePoint, Microsoft and vulnerability
Digest more
The name was coined by Dinh Ho Anh, a researcher from Khoa of Viettel Cyber Security, who developed the exploit. The researcher said he picked the name because it exploited ToolPane.aspx, a component for assembling the side panel view in the SharePoint user interface.
4don MSN
Microsoft SharePoint zero-day breach hits 75 servers: Here’s what the company said on the attack
A critical zero-day vulnerability, CVE-2025-53770, is actively exploited in Microsoft SharePoint, impacting 75 company servers, including major corporations and US government agencies. This flaw allows unauthenticated remote code execution.
The 130 CVEs (Common Vulnerabilities and Exposures) disclosed in Microsoft’s monthly release of security fixes includes a remote code execution flaw that ‘definitely’ should be prioritized for patching,
Researchers first uncovered a sweeping cyber espionage operation targeting Microsoft server software affecting at least 100 organisations.
Microsoft’s real definition of critical seems to be what they define as Important: “A vulnerability whose exploitation could result in compromise of the confidentiality, integrity, or ...
In the last 12 months Microsoft has released 139 security bulletins; 55 of them have a severity rating of 'Critical' and 84 of them 'Important.' The point of these severity ratings is a noble one ...