Microsoft has issued an urgent security update to address two critical zero‑day vulnerabilities—CVE‑2025‑53770 and CVE‑2025‑53771—in on‑premises SharePoint Server. These flaws, collectively exploited under the code name ToolShell, allow unauthenticated remote code execution (RCE) and path‑traversal spoofing, severely endangering enterprise environments worldwide
What are the vulnerabilities?
- CVE‑2025‑53770: A high-severity RCE flaw (CVSS 9.8) resulting from unsafe deserialization of untrusted data. It enables attackers to run arbitrary code before authentication, facilitating full server compromise .
- CVE‑2025‑53771: A spoofing-path traversal issue (CVSS 6.3) that lets authenticated attackers manipulate file paths to create spoofed content—a vulnerability Microsoft has now bolstered with new protections.
Both vulnerabilities were previously linked to other earlier patched vulnerabilities—CVE‑2025‑49704 and CVE‑2025‑49706—in what’s been described as a powerful attack chain. The new patches offer “more robust protections” compared to those previously applied.
Active exploitation and compromised targets
Groups like Eye Security first detected active exploitation of these flaws around July 18, 2025, noting that at least 54 organizations—including banks, universities, and government entities—have been compromised. Evidence of shell deployment indicates attackers obtained cryptographic machine keys, allowing them to forge legitimate server requests through __VIEWSTATE tampering and persist in infected environments even after reboot or patching.
Advisories from Palo Alto Networks’ Unit 42 warn that:
“Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors, and stealing cryptographic keys. If you have SharePoint on‑prem exposed to the internet, you should assume that you have been compromised.”
Beyond the initial exploits, victims span hundreds of servers globally, compromising critical sectors like government, education, healthcare, energy, and finance.
How Microsoft responded
Microsoft released tailored emergency updates on July 21, 2025, for:
- SharePoint Server 2019 (build 16.0.10417.20027)
- SharePoint Server Subscription Edition
- SharePoint Enterprise Server 2016 (partial; broader patch pending)
The company urged customers to:
- Apply patches immediately
- Enable Antimalware Scan Interface (AMSI) and run Defender Antivirus in full mode
- Rotate ASP.NET machine keys and restart IIS on all SharePoint servers
CISA added CVE‑2025‑53770 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch by July 21, 2025.
Recommended incident response measures
Experts emphasize that patching alone isn’t enough. Administrators are strongly advised to:
- Rotate all cryptographic keys post-patch to invalidate any stolen credentials .
- Disconnect vulnerable SharePoint servers from internet exposure until fully secured and validated
- Conduct full incident investigations, including log analysis for unusual activity and checking for anomalous
__VIEWSTATEpayloads - Deploy endpoint detection tools like Defender for Endpoint to detect lateral movements or backdoors
- Consider professional Incident Response (IR) support, especially for networks known to be compromised
Implications for cybersecurity
This breach reveals how zero‑days in widely used platforms like SharePoint can serve as potent entry vectors. The theft of cryptographic keys not only enables persistent access but also undermines trust in existing security patches—if keys aren’t rotated, previous solutions are rendered ineffective
Moreover, since SharePoint often integrates with services like Teams, OneDrive, Outlook, and more, attackers can exploit a compromised server to breach broader organizational systems
Ultimately, the incident underscores the critical importance of:
- Proactive vulnerability management
- Segmentation and limiting internet exposure
- Comprehensive IR and recovery protocols
- Rapid response to newly discovered zero-days
Organizations running on-premises SharePoint must act swiftly: update patched versions, rotate keys, audit systems, and fortify detection capabilities. Time is of the essence—delay could mean deep infiltration and prolonged compromise.
Please subscribe to the Newsletter so that you do not miss any critical update
