UK Microsoft Office SharePoint Server vulnerability found – remediate now
News|24 July 2025
Are you using SharePoint on-premises?
Microsoft has released a security notice regarding a on-premises SharePoint server vulnerability, cve-2025-52770.
The NCSC has said that this vulnerability allows an attacker to remotely execute arbitrary code via the deserialisation of untrusted data. A separate vulnerability, CVE-2025-53771, allows this attack to be performed while bypassing your authentication.
If you have any of the following products, you're affected by this vulnerability:
- Microsoft SharePoint Server Subscription Edition
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server 2016
How to fix the SharePoint server vulnerability
Microsoft and NCSC have advised that you take the following steps as soon as possible:
- Use supported versions of on-premises SharePoint Server
- Apply the latest security updates
- Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions
- Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an appropriate antivirus solution such as Defender Antivirus
- Rotate SharePoint Server ASP.NET machine keys
The NCSC has guidance on vulnerability management, an early warning notification service, and a vulnerability disclosure toolkit.
Need help improving your security?
Create a better defence against threats and spot vulnerabilities before they become an issue.
We can help you with Microsoft Defender for Endpoint, threat protection and antivirus solutions. Book a call with our security expert now. Fill in the form below or call +44 (0) 1364 655181. He can take you through the seven layers of security and identify gaps that need remediating to make your security posture more robust.
Contact Grey Matter
If you have any questions or want some extra information, complete the form below and one of the team will be in touch ASAP. If you have a specific use case, please let us know and we'll help you find the right solution faster.
By submitting this form you are agreeing to our Privacy Policy and Website Terms of Use.
Related News
We’re now a Kiteworks reseller partner
We’re excited to announce that we’re now a Kiteworks reseller partner to help you improve your file sync and sharing experiences, as well as improve security best practices. “Having Kiteworks as a partner enables us to deliver secure, enterprise-grade Managed File Transfer, File Share and Collaboration, and...
See you at the International Cyber Expo
Tue 29 September 2026 - Tue 30 June 2026 10:00 am - 5:00 pm BST
We’re exhibiting at the International Cyber Expo We’re excited to share that we’ve got stand at the International Cyber Expo at Olympia, London, for the very first time. 29-30 September 2026. You’ll find us on stand K60, where our team will be ready...
We’re returning as a gold sponsor at Agile on the Beach 2026
Agile on the Beach is where businesses come together to learn, share and move forward on their Agile journey. Agile methodologies. A community of thought leaders. Workshops with practical applications. You don’t want to miss out. We’re proud to be returning as a Gold sponsor for Agile on the...
The invisible scar: Why ransomware is a mental health crisis, not just a financial one
When a ransomware attack hits the news, the headlines are almost always dominated by the “big numbers”: a £5 million ransom demand, a 40% drop in stock price, or the multi-million-pound cost of system restoration. While these figures are staggering, they...