SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

A Critical SharePoint Flaw Enables Remote Code Execution, Exposing Users Worldwide

Microsoft has acknowledged a critical vulnerability in its widely-used collaboration platform, SharePoint. Initially listed as a spoofing issue, the flaw was later found to allow an attacker with authenticated access to execute arbitrary code remotely. This significant security weakness affects a vast number of users worldwide who rely on SharePoint for business operations.

The vulnerability, which is now being actively exploited by threat actors, stems from a privilege escalation mechanism in SharePoint’s cross-domain feature. Normally designed to facilitate seamless communication between different domains within an organization’s network, this feature has been compromised, allowing attackers to bypass security checks and execute malicious code with elevated privileges. Once inside the system, an attacker can move laterally across the network, accessing sensitive data and inflicting significant damage.

The root cause of the issue lies in the way SharePoint handles requests from external domains. When a request is made from one domain to another, SharePoint verifies the identity of the sender but fails to properly validate their privileges. This weakness allows an attacker with valid credentials to elevate their permissions and execute code on the server. The exploit is particularly concerning because it can be carried out by an authenticated user, meaning that even employees who are supposed to have access to sensitive data may inadvertently enable a breach.

The scope of this vulnerability extends far beyond individual organizations. With SharePoint being used by millions worldwide, the potential for widespread damage is immense. Furthermore, the fact that attackers require only valid credentials to execute the exploit means that even users with limited privileges can unwittingly compromise their company’s security.

Microsoft has released an emergency patch to address the issue, and it’s essential for all affected organizations to apply this update as soon as possible. However, it’s also crucial to recognize that vulnerability exposure often starts with identity-related issues. To mitigate such risks in the future, companies should prioritize robust authentication and authorization mechanisms, ensuring that access controls are properly configured and regularly reviewed.

In light of this critical flaw, it’s essential for users to remain vigilant and ensure their systems are up-to-date. By doing so, they can minimize the risk of falling victim to this exploit and other similar threats.


Source: The Hacker News — 2026-09-22