Jul 23, 2025

Vulnerability in SharePoint 2019/SharePoint 2016

If you use Microsoft Identity Manager 2016, including the Portal, and SharePoint, the following is useful to know:

There is a vulnerability in SharePoint 2019 and SharePoint 2016 that is currently being actively exploited and has been warned about, see:

Latest update: Vulnerabilities in Microsoft SharePoint Server actively exploited | News item | National Cyber ​​Security Center

Microsoft has released a customer guidance document explaining what to do, see:

https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/

For the version of SharePoint that you have operational, you need to do the following:

  1. Install the SharePoint July 2025 update:
    SP2019: https://support.microsoft.com/help/5002741
    SP2016: https://support.microsoft.com/help/5002744
  2. Install the security update for the vulnerability
    SP2019: https://www.microsoft.com/en-us/download/details.aspx?id=108286
    SP2016: https://www.microsoft.com/en-us/download/details.aspx?id=108288
  3. Configure ‘Antimalware Scan Interface (AMSI)’ integration in SharePoint as indicated in the article.
    Note: not all SharePoint versions support this (option unavailable); in this case, it’s important to install the patches and follow step 5 below.
  4. Make Microsoft Defender for Endpoint available as indicated in the article.
    Note: This is a paid service within the Azure Tenant and may not be available to you. In this case, it’s important to install the patches and follow step 5 below.
  5. Rotate SharePoint Server ASP.NET machine keys as indicated in the article.
    Note: The patches must be installed first. After updating the machine keys, perform an IISRESET on all SharePoint servers.
    The “web application” name is often “MIM Portal.” If you’re unsure, look up the web application for MIM Portal in SharePoint Central Admin.
    The command is ‘Update-SPMachineKey -WebApplication “MIM Portal”’ and should be run with a “Farm Admin” account in SharePoint (we introduced the “MIM Installer” account for this purpose, which is “Farm Admin”).

If you would like assistance with the implementation of the above, please contact us via
info@trusted-id.eu