# ثغرة في «مايكروسوفت شير بوينت» ممكن توصلك وتخترق معلوماتك.. هل تؤثر على مصر؟

Source: https://www.youtube.com/watch?v=ls0kl3ElJkQ
Recap page: https://rapidrecap.app/video/ls0kl3ElJkQ
Generated: 2025-07-22T13:04:11.377+00:00

---
## Quick Overview

A critical zero-day vulnerability in Microsoft SharePoint Server 2016 and 2019 allows hackers to access sensitive organizational data, including passwords and network designs. This vulnerability does not affect cloud-based Office 365 SharePoint. Organizations using the affected on-premise versions must immediately isolate servers, apply updates, change passwords, and implement robust log analysis to prevent further exploitation.

**Key Points:**
- A critical zero-day vulnerability affects Microsoft SharePoint Server 2016 and 2019, allowing hackers to access sensitive data.
- The vulnerability specifically targets on-premise SharePoint installations, not cloud-based Office 365 services.
- Hackers can steal confidential information, including passwords, network diagrams, and other important files.
- Federal agencies, universities, and companies in critical sectors like energy and telecommunications are at risk.
- Egyptian banks are largely unaffected due to regulations that prevent storing sensitive data on cloud services.
- Organizations with affected SharePoint versions must immediately isolate servers, apply updates, and change passwords.
- More widespread global attacks are anticipated as a result of this newly discovered vulnerability.

![Screenshot at 0:00: Split screen showing Microsoft building logo and a news anchor, with a text overlay warning about a zero-day attack on SharePoint.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-00-00.png)

**Context:** Microsoft SharePoint is a widely used collaboration platform for file sharing and document management within organizations. A 'zero-day' vulnerability refers to a software flaw that is unknown to the vendor (Microsoft, in this case) and therefore has no patch available when attackers first exploit it. This video discusses a recent zero-day vulnerability discovered in specific on-premise versions of Microsoft SharePoint Server, highlighting its potential impact on various entities globally.

## Detailed Analysis

Microsoft has issued a warning regarding a critical zero-day vulnerability affecting its on-premise SharePoint Server 2016 and 2019 versions. This flaw allows unauthorized access to sensitive organizational data, including critical passwords, network diagrams, and other confidential files. The expert, Engineer Amr Sobhy, clarifies that Microsoft's cloud-based Office 365 SharePoint service is not impacted, as its servers are managed directly by Microsoft. The danger lies with organizations that have purchased and installed SharePoint servers locally, as these systems may lack the necessary, timely updates from Microsoft to patch the newly discovered vulnerability. This 'zero-day' nature means Microsoft itself was unaware of the flaw until it was exploited, potentially allowing hackers to reside undetected on compromised servers for extended periods, extracting vast amounts of data. Affected entities globally include federal agencies, universities, and companies in critical sectors like energy and telecommunications. While Egyptian banks are largely unaffected due to regulations preventing sensitive data storage on cloud services, any local entity using the vulnerable SharePoint versions is at risk. The expert stresses the urgency for IT professionals to isolate affected servers, apply all available updates, change system passwords, and utilize log analysis tools to detect and mitigate any ongoing intrusions, as more widespread attacks stemming from this vulnerability are anticipated.

### Vulnerability Overview

- A zero-day vulnerability exists in Microsoft SharePoint Server 2016 and 2019, allowing unauthorized access to sensitive data.
- This vulnerability is critical because Microsoft was initially unaware of it, giving attackers a 'zero-day' advantage.

### Affected Systems

- The vulnerability specifically impacts on-premise installations of SharePoint Server 2016 and 2019.
- Cloud-based Microsoft Office 365 SharePoint is not affected, as its infrastructure is managed directly by Microsoft.

### Impact on Organizations

- Hackers can access highly sensitive data, including administrator passwords, network diagrams, and critical files.
- Federal agencies, universities, energy companies, and telecommunication firms globally have been identified as potential targets.
- Attackers can remain undetected on compromised servers for extended periods, continuously exfiltrating data.

### Local Impact (Egypt)

- Egyptian banks are generally safe as they do not typically store sensitive data on cloud services, adhering to local regulations.
- However, any Egyptian organization using the vulnerable on-premise SharePoint versions is at risk.

### Mitigation and Prevention

- Organizations must immediately isolate affected SharePoint servers to prevent further data breaches.
- Applying all available Microsoft updates and changing system passwords are crucial first steps.
- Implementing robust log analysis and threat hunting tools is essential to detect and respond to hidden intrusions.

![Screenshot at 0:00: Split screen showing Microsoft building logo and a news anchor, with a text overlay warning about a zero-day attack on SharePoint.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-00-00.png)
![Screenshot at 0:41: News segment showing the Microsoft logo and building, with a text overlay identifying the guest as Engineer Amr Sobhy, an information security expert.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-00-41.png)
![Screenshot at 1:39: Close-up shot of Engineer Amr Sobhy, the information security expert, explaining the technical details of the SharePoint vulnerability.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-01-39.png)
![Screenshot at 2:19: Close-up of the expert emphasizing the severity of the zero-day vulnerability and its implications for data security.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-02-19.png)
![Screenshot at 3:24: Close-up of the expert explaining the concept of a 'zero-day attack' where the software vendor is unaware of the vulnerability.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-03-24.png)
![Screenshot at 4:25: Close-up of the expert discussing the potential for long-term undetected presence of hackers on compromised servers.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-04-25.png)
![Screenshot at 5:06: Close-up of the expert smiling while discussing the security measures taken by Egyptian banks, which largely protect them from this specific cloud-related vulnerability.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-05-06.png)
![Screenshot at 5:34: Close-up of the expert advising IT professionals on immediate actions to secure their SharePoint servers against the vulnerability.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-05-34.png)
![Screenshot at 6:01: Close-up of the expert stressing the importance of using original software versions and applying updates to prevent vulnerabilities.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-06-01.png)
![Screenshot at 7:21: Close-up of the expert explaining how log analysis tools can help identify if a system has been compromised by a zero-day attack.](https://ss.rapidrecap.app/screens/ls0kl3ElJkQ/00-07-21.png)
