AI Security AI安全 5h ago Updated 2h ago 更新于 2小时前 49

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC 关键SharePoint远程代码执行漏洞CVE-2026-50522在公开PoC后正被主动利用

CVE-2026-50522 is a critical (CVSS 9.8) Remote Code Execution vulnerability in Microsoft SharePoint Server involving deserialization of untrusted data, currently under active exploitation. WatchTowr and Defused Cyber report that attackers are leveraging public Proof-of-Concept (PoC) exploits to steal IIS machine keys for persistent access without requiring authentication. This is the third SharePoint vulnerability patched in July 2026 to see active exploitation, following CVE-2026-56164 and CVE- Microsoft SharePoint Server 曝出严重反序列化漏洞 CVE-2026-50522 (CVSS 9.8),已在公开 PoC 发布后遭到活跃利用。 攻击者可通过网络远程执行代码,窃取 IIS 机器密钥以维持持久化访问,且无需身份验证即可实施部分攻击。 CISA 警告称,包括 CVE-2026-50522 在内的多个 SharePoint 漏洞正被用于获取对本地部署实例的未授权访问。 受影响版本涵盖所有支持的本地 SharePoint Server(Subscription Edition, 2019, 2016),仅打补丁不足以消除风险,需立即轮换凭证。

75
Hot 热度
65
Quality 质量
70
Impact 影响力

Analysis 深度分析

TL;DR

  • CVE-2026-50522 is a critical (CVSS 9.8) Remote Code Execution vulnerability in Microsoft SharePoint Server involving deserialization of untrusted data, currently under active exploitation.
  • WatchTowr and Defused Cyber report that attackers are leveraging public Proof-of-Concept (PoC) exploits to steal IIS machine keys for persistent access without requiring authentication.
  • This is the third SharePoint vulnerability patched in July 2026 to see active exploitation, following CVE-2026-56164 and CVE-2026-58644, which were previously weaponized as zero-days.
  • CISA warns that these flaws affect all supported on-premises SharePoint versions (2016, 2019, Subscription Edition) and enable post-exploitation activities like malware deployment.

Why It Matters

This incident highlights the severe risk of delayed patching for high-severity vulnerabilities in widely deployed enterprise infrastructure, particularly when public PoCs are immediately available. For security practitioners, it underscores the necessity of immediate credential rotation and monitoring for anomalous deserialization traffic, as patching alone does not mitigate damage already inflicted by active attackers.

Technical Details

  • Vulnerability Mechanism: CVE-2026-50522 allows remote code execution via deserialization of untrusted data, enabling unauthorized code injection by attackers with at least Site Owner privileges or potentially unauthenticated users depending on the specific attack vector observed.
  • Exploit Activity: Threat actors are executing single-request attacks to extract SharePoint/IIS machine keys, facilitating session hijacking and persistent access across the network.
  • Affected Scope: All supported on-premises versions of SharePoint Server, including Subscription Edition, 2019, and 2016, are vulnerable to these combined exploitation efforts.
  • Related Vulnerabilities: The current exploitation campaign is part of a broader wave affecting CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, indicating a coordinated focus on SharePoint's deserialization and authentication mechanisms.

Industry Insight

  • Immediate Remediation Priority: Organizations must prioritize patching SharePoint servers and rotating all associated machine keys and credentials immediately, as passive patching is insufficient once keys are stolen.
  • Enhanced Monitoring: Security teams should implement strict monitoring for unusual deserialization patterns and outbound connections from SharePoint servers to detect post-exploitation activities like malware deployment.
  • Zero-Day Preparedness: The rapid transition of these vulnerabilities from discovery to active exploitation suggests that defenders should assume public disclosures of critical infrastructure flaws may be accompanied by immediate, widespread attack campaigns.

TL;DR

  • Microsoft SharePoint Server 曝出严重反序列化漏洞 CVE-2026-50522 (CVSS 9.8),已在公开 PoC 发布后遭到活跃利用。
  • 攻击者可通过网络远程执行代码,窃取 IIS 机器密钥以维持持久化访问,且无需身份验证即可实施部分攻击。
  • CISA 警告称,包括 CVE-2026-50522 在内的多个 SharePoint 漏洞正被用于获取对本地部署实例的未授权访问。
  • 受影响版本涵盖所有支持的本地 SharePoint Server(Subscription Edition, 2019, 2016),仅打补丁不足以消除风险,需立即轮换凭证。

为什么值得看

该事件揭示了企业级协作平台在底层反序列化机制上的深层安全隐患,展示了从漏洞披露到大规模活跃利用的快速转化路径。对于负责微软生态安全的企业而言,这是一次关于“补丁不等于安全”的紧急警示,强调了凭证轮换和纵深防御在应对已知漏洞时的必要性。

技术解析

  • 漏洞机制:CVE-2026-50522 属于不受信任数据的反序列化漏洞,允许未经授权的攻击者通过网络远程执行代码 (RCE)。其攻击向量标记为网络 (AV:N),复杂度低 (AC:L),意味着无需复杂前置知识即可重复成功利用。
  • 利用方式:威胁行为者利用公开的 PoC 向 SharePoint 登录端点投递 .NET 反序列化载荷。Defused Cyber 指出,捕获的请求中不包含认证材料,符合该漏洞无认证利用的特征。
  • 持久化手段:攻击的核心目标之一是提取 SharePoint/IIS 机器密钥。通过单次请求即可窃取密钥,从而维持对服务器的持久化访问权限,并进一步部署恶意软件。
  • 影响范围:所有受支持的本地 SharePoint Server 版本均受影响,包括 Subscription Edition、2019 和 2016 版本。这是继 CVE-2026-56164 和 CVE-2026-58644 之后,第三个被证实遭活跃利用的 SharePoint 漏洞。

行业启示

  • 应急响应策略升级:面对 CVSS 9.8 的高危漏洞及活跃的零日/近零日利用,单纯的软件修补已不足够。安全团队必须立即执行凭证轮换(特别是机器密钥和管理员账户),以切断攻击者的持久化路径。
  • 本地部署风险加剧:随着云服务的普及,本地 SharePoint 部署常被忽视,但此次事件表明其仍是高价值攻击目标。企业应重新评估本地基础设施的安全监控力度,特别是针对反序列化攻击的检测规则。
  • 供应链与第三方依赖管理:微软 Patch Tuesday 期间连续出现多个高危漏洞,反映出大型软件平台在复杂组件(如 .NET 反序列化引擎)中的潜在脆弱性。组织需建立更敏捷的漏洞响应机制,以应对密集发布的补丁周期中的连锁风险。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究