CyberzSOC

Publication detail
← Back to advisories & guidance

CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities ↗ source

August 6, 2025 CISA Analysis Report

Summary

CISA analyzed six files including two Dynamic Link-Library (.DLL), one cryptographic key stealer, and three web shells. Cyber threat actors could leverage this malware to steal cryptographic keys and execute a Base64-encoded PowerShell command to fingerprint host system and exfiltrate data. CISA added CVE-2025-49704 and CVE-2025-49706 to its Known Exploited Vulnerabilities Catalog on July 22, 2025, and CVE-2025-53770 on July 20, 2025. Downloadable copy of IOCs associated with this malware: Downloadable copies of the SIGMA rule associated with this malware: For more information on the malware files and YARA rules for detection, see MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities . The information in this report is being provided “as is” for informational purposes only.

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2025-53770

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-53770 9.8 Critical Microsoft SharePoint Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execu…
CVE-2025-49704 8.8 High Microsoft SharePoint Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerabili…
CVE-2025-49706 6.5 Medium Microsoft SharePoint Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Success…
CVE-2025-53771 6.5 Medium Microsoft Microsoft SharePoint Enterprise Server 2016 Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.