Skip to main content
Mallory
MediumCISA KEVExploited in the wildPublic exploit

Improper authentication spoofing vulnerability in Microsoft Office SharePoint

IdentifiersCVE-2025-49706CWE-287· Improper Authentication

CVE-2025-49706 is an improper authentication / spoofing vulnerability affecting on-premises Microsoft Office SharePoint Server. Microsoft describes it as allowing an unauthorized attacker to perform spoofing over a network. Reporting in the provided content consistently ties the flaw to authentication bypass behavior on exposed SharePoint servers, including exploitation via crafted requests to SharePoint functionality such as the ToolPane endpoint as part of the broader "ToolShell" exploit chain. The vulnerability affects on-premises SharePoint deployments, not SharePoint Online in Microsoft 365, and has been observed chained with CVE-2025-49704 to achieve remote code execution and post-exploitation access.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

On its own, the vulnerability enables spoofing / authentication bypass against vulnerable on-premises SharePoint servers. In observed real-world attacks, it has been used as part of an exploit chain to obtain unauthorized access to SharePoint, facilitate subsequent remote code execution when combined with CVE-2025-49704, and support deployment of web shells, theft of ASP.NET MachineKey material, persistence, credential theft, lateral movement, and in some cases ransomware deployment. Reporting in the provided content states that successful exploitation can expose SharePoint file systems and connected services and has been used in widespread attacks against enterprises and government organizations.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce or remove internet exposure of on-premises SharePoint servers. The provided content recommends disconnecting exposed SharePoint servers from the internet where necessary, or limiting unauthenticated access through a VPN, proxy requiring authentication, or an authentication gateway. Additional mitigations mentioned include enabling AMSI in SharePoint, preferably Full Mode HTTP request body scanning, deploying Microsoft Defender Antivirus / Defender for Endpoint or equivalent protections, rotating SharePoint ASP.NET machine keys after patching, and restarting IIS. Monitoring for creation of suspicious ASPX files such as spinstall0.aspx and anomalous w3wp.exe child process activity is also indicated by the content.

Remediation

Patch, then assume compromise.

Apply Microsoft's security updates for affected on-premises SharePoint versions. The provided content states Microsoft released fixes for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, and that later comprehensive updates also addressed related variant vulnerabilities CVE-2025-53770 and CVE-2025-53771. Organizations should ensure they are running supported SharePoint versions and install the latest cumulative security updates immediately.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.

VALID 0 / 2 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationSharepoint Enterprise Serverapplication
Microsoft CorporationSharepoint Serverapplication
Microsoft CorporationSharepoint Server 2016application
Microsoft CorporationSharepoint Server 2019application

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence26

Every observed campaign linking this CVE to a named adversary.

Associated malware24

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity114

Community discussion across Reddit, Mastodon, and other social sources.