HWS Logo

Security vulnerability in SharePoint: zero day

SharePoint Zero-Day Vulnerability: On-Premises Customers Targeted by Hackers 

In a digital landscape increasingly threatened by cyberattacks and data breaches, protecting your company’s data is more critical than ever. Organizations using traditional SharePoint on-premises systems are now more than ever in the crosshairs of cybercriminals. Two severe zero-day vulnerabilities in Microsoft SharePoint have recently been disclosed, putting sensitive business data at risk and potentially allowing unrestricted access to hackers. 

Systems affected by the SharePoint security vulnerability

The following SharePoint versions are impacted by these vulnerabilities: 

  • SharePoint Enterprise Server 2016 
  • SharePoint Server 2019 
  • SharePoint Server Subscription Edition 

 

While emergency updates have been issued for SharePoint Server 2019 and Subscription Edition, a patch for SharePoint 2016 is still pending as of July 21, 2025. 

Risks of Traditional SharePoint On-Premises Installations

On-premises systems pose significant security challenges because they: 

  • Require continuous maintenance and independent patch management. 
  • Often have outdated installations that do not address vulnerabilities promptly. 
  • Represent underestimated risks due to publicly known but unpatched security gaps. 
  • Incur a high workload to comply with legal and regulatory requirements. 

 

These factors make local SharePoint installations a particularly attractive target for attacks. 

Why SharePoint Online Is the Secure Alternative

Moving to SharePoint Online offers numerous advantages and a significantly higher level of security, as Microsoft continuously develops and provides state-of-the-art cloud security and compliance measures worldwide. The most important advantages include:

State-of-the-art encryption and infrastructure

  • Data encryption:All data is protected with strong encryption standards such as AES-256 both during transmission and at rest.
  •  Files are broken down into encrypted parts and distributed across different geographical locations to make unauthorised access more difficult.

Permanent security updates

  •  Critical security vulnerabilities are closed centrally and automatically without manual intervention by your IT team.
  •  Microsoft monitors the environment around the clock for attacks and suspicious activity.

enhanced authentication and access control

  • Multi-factor authentication (MFA): Effectively protects user accounts from unauthorised access, even if passwords are compromised.
  • Granular rights management: Enables precise control over who can access which data to prevent misuse.
  • Conditional Access: Conditional Access only allows access to data under certain conditions (e.g. trusted devices or locations). This ensures a high level of protection even in changing work environments.

Compliance & Data Protection

  • Regulatory certifications: SharePoint Online complies with important international standards such as GDPR and ISO.
  • Data protection features: Data Loss Prevention (DLP), security labels and automated reports help protect sensitive information.

Controlled sharing and external collaboration

  •  You always have an overview of which data is shared with whom, even across external partners.
  •  Temporary access rights for external users prevent unauthorised permanent access.

Dangers Posed by the SharePoint Zero-Day Vulnerability

Attackers exploiting this vulnerability can steal cryptographic “machine keys.” With these keys, hackers may repeatedly access your system even after the initial flaw is patched. This enables attackers to impersonate legitimate users or services, install backdoors, or compromise other systems within your network. 

Don’t Take Unnecessary Risks

The emergence of this zero-day vulnerability highlights that local SharePoint installations are a prime target for cybercriminals because they are often patched late and are harder to secure than modern cloud solutions. 

As your trusted IT partner, we support your migration to SharePoint Online—from thorough planning to a successful go-live. Protect your sensitive data efficiently and prepare your business for the digital future. 

Feel free to contact us for a no-obligation consultation and secure your company optimally! 

More on the topic of cloud computing

More on the topic of cloud computing

More Articles

Whitepaper Windows 11 via
Microsoft Intune

Our new white paper: Download now!

Best practices, costs and use cases for the Windows 11 rollout in over 20 pages! Free for a limited time only!

IT Projects

Find out about our IT projects and customer success stories up close now.

HWS is looking for you

We are always looking for motivated talents who want to help shape our company. With us, you can expect challenging work in IT and a dynamic, inclusive corporate culture.

HWS AT A GLANCE

Find out who we are and what drives us. Immerse yourself and discover our passion for technology, innovation and excellence, made in Franconia