A SharePoint Server vulnerability initially classified by Microsoft as a medium-severity spoofing flaw has been proven to enable authenticated Remote Code Execution (RCE), demanding immediate reassessment and emergency patching across affected on-premises deployments.
The flaw, tracked as CVE-2026-65660, affects Microsoft SharePoint Server 2016, 2019, and Subscription Edition. In its original advisory, Microsoft assigned the vulnerability a CVSS base score of 6.5 and categorized it as a "Spoofing" issue—a classification that significantly understated the true risk. Full technical analysis published by Viettel Cyber Security researcher Dinh Ho Anh Khoa demonstrates that an attacker with valid credentials can exploit the flaw to execute arbitrary code on the host server.
This severity upgrade fundamentally changes the threat profile. What was initially perceived as a potential data deception attack is, in fact, a full system compromise vector. An authenticated adversary could leverage the vulnerability to take complete control of affected SharePoint servers, exfiltrate sensitive data, or deploy malware across the network.
The primary attack path requires valid user credentials, meaning the exploit relies on compromised accounts or malicious insiders. This underscores the need for robust identity and access controls alongside timely patching.
Immediate Actions for Administrators: * Patch Without Delay: Apply Microsoft's security update for CVE-2026-65660 as a critical emergency priority for all affected on-premises SharePoint deployments. * Mitigate if Necessary: Where immediate patching is not feasible, enforce strict access controls limiting SharePoint access to essential personnel and deploy enhanced monitoring for anomalous activity.
The incident reinforces an enduring lesson in vulnerability management: vendor-assigned severity ratings provide a useful baseline but should never be the sole determinant of remediation priority. Security teams are advised to maintain informed skepticism, supplementing official advisories with independent research to accurately assess real-world risk and allocate resources accordingly.
一個微軟最初分類為中等嚴重程度欺騙漏洞的SharePoint伺服器安全缺陷,已被證實可實現經認證的遠端程式碼執行(RCE),需要對所有受影響的本機部署立即進行重新評估及緊急修補。
該漏洞被追蹤為CVE-2026-65660,影響Microsoft SharePoint Server 2016、2019及訂閱版。微軟最初的安全公告賦予此漏洞CVSS基本分數6.5,並將其歸類為「欺騙」問題——這一分類嚴重低估了實際風險。越南電信網絡安全研究員Dinh Ho Anh Khoa發表的完整技術分析顯示,持有有效憑證的攻擊者可利用此漏洞在主機伺服器上執行任意程式碼。
這次嚴重程度的升級從根本上改變了威脅特徵。最初被認為是潛在數據欺騙攻擊的漏洞,實際上是一條完全系統入侵的途徑。經認證的攻擊者可利用此漏洞完全控制受影響的SharePoint伺服器、竊取敏感數據,或在網絡中部署惡意軟件。
主要攻擊途徑需要有效的用戶憑證,這意味著漏洞利用依賴於被入侵的帳戶或惡意內部人員。這突顯了在及時修補的同時,亦需實施強大的身份驗證和存取控制。
管理員需立即採取行動: * 毫不延遲地進行修補: 將微軟針對CVE-2026-65660的安全更新列為所有受影響本機部署SharePoint伺服器的緊急最高優先級。 * 在必要時採取緩解措施: 若無法立即修補,請實施嚴格的存取控制將SharePoint存取限制於必要人員,並部署強化監控以偵測異常活動。
此事件重申了漏洞管理中一個持久的教訓:供應商分配的嚴重程度評級提供了有用的基準,但絕不應成為補救優先順序的唯一決定因素。建議安全團隊保持有根據的質疑精神,透過獨立研究補充官方公告,以準確評估實際風險並相應分配資源。
