# Rapid7 Published the PoC. Attackers Weaponized It Within Hours.
The proof-of-concept sat on the internet for less than a day before someone pointed it at a real target.
Rapid7 published technical exploit code Tuesday for a critical Microsoft SharePoint vulnerability — the kind of detailed, reproducible PoC that turns a patching advisory into a countdown clock. By the time most enterprise security teams finished their morning coffee, threat actors had already begun adapting the code for active attacks. That turnaround is not a surprise to anyone who has been watching this pattern. It should be, though, because the window keeps getting shorter.
## The Vulnerability
The flaw lives in SharePoint Server — Microsoft's on-premises collaboration platform that sits at the nervous center of thousands of enterprise environments. SharePoint handles document management, intranet portals, workflows, and in many organizations, it's the connective tissue between Active Directory and everything else. When SharePoint falls, it rarely falls alone.
The vulnerability is rated critical. Microsoft patched it, as Microsoft does, and the expectation — always optimistic, never accurate — is that organizations apply patches before anyone reverses the fix and reconstructs the attack path. Rapid7's researchers did that reconstruction, published the results as a PoC for research and defensive purposes, and within hours, attackers had proof that the work was solid.
The specific attack surface matters here. SharePoint vulnerabilities tend to attract sophisticated actors precisely because of what SharePoint touches. It's not just file storage — it's authentication integration, it's email, it's often the gateway to broader internal network access. A foothold in SharePoint is frequently a foothold in far more.
## The PoC Economy
Rapid7's decision to publish deserves scrutiny, not condemnation. The security industry has had this argument for two decades and hasn't resolved it. Vendors argue that PoC publication gives attackers a free toolkit. Researchers argue that without PoC details, defenders can't accurately assess risk, vendors face less pressure to patch urgently, and the bad actors — who share exploit code in private channels long before any public disclosure — hold a structural advantage over defenders.
That last point is empirically correct. The belief that publishing a PoC "creates" a threat rather than surfacing one that already exists is largely a comforting fiction. What changes after public PoC release isn't whether exploitation happens — it's who can do it. Before publication, exploitation requires serious reverse-engineering skill. After publication, the barrier drops to "can you follow instructions."
The gap between those two populations is not trivial. But the gap between "patch available" and "patch applied" in enterprise SharePoint environments is, apparently, smaller than ever required.
## What Unpatched SharePoint Looks Like From the Outside
Most SharePoint Server deployments are not patched quickly. That's not an opinion — Microsoft's own data on patch adoption rates, and the pattern of prior SharePoint exploits, makes this plain. CVE-2019-0604 was a SharePoint RCE flaw that threat actors were actively exploiting more than a year after Microsoft released the fix. The pattern repeated with CVE-2020-16952, with the ProxyNotShell-adjacent SharePoint bugs in 2022, and with the authentication bypass chain that made news in 2023.
Every time, the same arc: patch drops, PoC follows, exploitation begins, incident reports pile up, and organizations scramble to determine whether they were hit before or after they patched.
On-premises SharePoint in particular lags. Cloud-hosted SharePoint Online gets Microsoft's patches applied automatically — enterprises running SharePoint Server on their own infrastructure carry the patching burden themselves. That population skews toward large, complex organizations with change management processes, testing requirements, and patching windows measured in weeks. Attackers know this. They specifically target on-premises SharePoint because the delay is predictable.
## Who Gets Hurt First
Historically, SharePoint exploits get picked up fast by:
The organizations most exposed right now are those running SharePoint Server on-premises without the patch, particularly in sectors with constrained IT resources or lengthy change approval cycles: healthcare, education, regional government, manufacturing. Large enterprises with sophisticated security operations will identify and patch quickly. The mid-market is where this typically gets ugly.
## What Defenders Actually Need to Do
Patching is the obvious answer. If you haven't applied the relevant update, stop reading and start that process.
For organizations still assessing their exposure:
Network segmentation matters here too. SharePoint should not have unrestricted lateral movement capability to the rest of your network. If it does, a compromise becomes a catastrophe.
---
## HackWire Analysis
The compressed timeline here — PoC published, active exploitation begins within hours — is the story underneath the story. What we're watching is not a novel threat technique. It is the logical endpoint of a decade-long trend: the professionalization of exploit development, the commodification of initial access, and the structural inability of enterprise patch cycles to keep pace with the threat.
The uncomfortable truth is that critical vulnerability disclosures for widely-deployed enterprise software now function less like warnings and more like starting pistols. The research community publishes to pressure vendors and equip defenders; attackers treat the same publications as product announcements.
What makes the SharePoint case particularly worth watching is context. SharePoint is not a peripheral application. In most large enterprise environments, it is deeply integrated with identity, email, document workflows, and internal applications. The blast radius of a successful SharePoint compromise is not contained to SharePoint. Incident responders who've worked SharePoint breaches consistently report that the real damage — domain privilege escalation, mass credential harvesting, ransomware deployment — comes after the initial foothold, not during it.
The organizations that will be hurt by this are the ones that always get hurt: mid-market, complex change processes, stretched IT teams, competing priorities. The solution is not a new tool or a new framework. It is the boring, unglamorous work of knowing what you're running and keeping it patched. The industry has been saying this for years. It keeps being true.
Rapid7 made the right call publishing the PoC. Holding it would have delayed defender understanding without meaningfully slowing attackers who move in private channels anyway. The frustration belongs elsewhere — directed at the conditions that make "patch your production SharePoint" a genuinely difficult operational ask for so many organizations.
— HackWire Editorial
---
## Related Coverage