Threat Intelligence Firms Warn of Government System Risks Due to Microsoft SharePoint Vulnerability

Share

Vulnerability in Microsoft SharePoint Server: An Overview

A serious vulnerability has emerged in Microsoft’s SharePoint Server, currently under active scrutiny by threat intelligence researchers. Notably, evidence has surfaced indicating that U.S. government systems may have been exposed and possibly compromised due to this flaw.

Scope of the Vulnerability

Microsoft has confirmed that this vulnerability affects on-premises versions of SharePoint, specifically SharePoint Enterprise Server 2016, 2019, and the Subscription Edition. Importantly, Microsoft 365 environments remain unaffected. The issue was first disclosed over the weekend, and by Sunday night, the company had rolled out patches for the 2019 version and the Subscription Edition.

The Nature of the Threat

Michael Sikorski, CTO and head of Threat Intelligence for Unit 42 at Palo Alto Networks, characterized this vulnerability as part of an ongoing “high-impact” threat campaign targeting on-premises SharePoint servers. According to Sikorski, entities in sectors like government, education, healthcare, and large enterprises are particularly vulnerable and face immediate risk.

He emphasized the urgency by stating, “This is a high-severity, high-urgency threat for exposed networks.” Organizations running on-premises SharePoint are advised to apply all relevant patches immediately, rotate cryptographic materials, and engage in professional incident response.

CISA’s Response

The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog. This designation mandates action from federal agencies, and CISA has indicated that there is active exploitation occurring in the wild. The agency’s alert has raised alarms, especially since the federal government extensively relies on Microsoft products for essential functions like file sharing and internal communication.

Technical Details of the Flaw

The vulnerability falls under the category of “zero-day,” meaning that developers were unaware of it before its disclosure and thus had no time to implement fixes. Hackers can exploit this flaw by sending specially crafted data to SharePoint servers, which could lead to unauthorized code execution without needing a password. Such vulnerabilities are notorious among malicious actors and pose significant risks, particularly in federal enterprises.

Global Impact and Findings

According to Netherlands-based cybersecurity provider Eye Security, an analysis of around 8,000 SharePoint servers revealed about 50 breaches. The Washington Post reported that at least two U.S. federal agencies fell victim to these attacks, with one incident involving the compromise of a SharePoint site used for public-facing documents.

Communication with Affected Entities

The Multi-State Information Sharing and Analysis Center (MS-ISAC) promptly alerted its members after being notified of the bug. Despite initial advisories sent to 50 entities, further investigations revealed more than 1,100 servers, spanning multiple sectors like education and government, were at risk due to their vulnerabilities.

Randy Rose, the VP of Security Operations at the Center for Internet Security, mentioned proactive outreach to affected entities and flagged the concerning number of servers at risk.

Challenges in Cyber Defense

The recent federal funding cuts to MS-ISAC have hindered its ability to provide proactive defenses and incident response for ongoing cyber campaigns. This reduction raises the stakes for state and local systems, putting a significant portion of American data at risk.

Mitigation Efforts by Cybersecurity Firms

CrowdStrike has indicated that it can detect and prevent exploitation of this SharePoint vulnerability. They are actively monitoring threat activity and consistently enhancing their protective measures. However, they have not disclosed specific information about affected customers.

Meanwhile, Google’s threat intelligence team confirmed that they have observed threat actors exploiting this vulnerability to install webshells. This type of access allows for persistent, unauthenticated control, presenting critical risks for organizations involved.

Recommendations for Organizations

Charles Carmakal, CTO of Mandiant, stressed that merely applying the patch is not sufficient. Organizations need to implement mitigations immediately and assume that compromises may have occurred prior to mitigation. He underscores the importance of thorough investigation and remediation actions as a priority.

Context of Previous Attacks

Microsoft systems have previously been targets of significant hacking attempts, including a highly publicized breach linked to Chinese actors that compromised thousands of emails from U.S. government agencies. This history underscores the ongoing vulnerabilities that technology systems face, highlighting the importance of vigilance in cybersecurity efforts.

Conclusion

The situation surrounding the SharePoint vulnerability is evolving rapidly, with significant implications not only for affected organizations but for the broader landscape of cybersecurity. As entities scramble to apply patches and bolster defenses, the lessons learned from this incident will be critical in shaping future responses to emerging threats in the digital realm.

Read more

Local News