Red warning symbol overlaying binary code

Vulnerabilities:

CVE-2025-53770 – 9.8 CRITICAL

CVE-2025-53771 – 6.5 MEDIUM

Executive Summary

Two zero-day vulnerabilities affecting on-premises Microsoft SharePoint servers have been recently reported with a CVSS rating of 9.8 and 6.5.  Microsoft released out-of-band patches for these vulnerabilities on 07/21/2025.  Unpatched servers are susceptible to an attack known as “ToolShell” which allows remote code execution on servers.  It is important to note that SharePoint Online in Microsoft 365 is NOT impacted.  The earliest reports of compromise are from 07/07/2025 and organizations are encouraged to apply these patches as soon as possible.

Details

  • On an unpatched server, attackers will send a malicious HTTP request to a process that serializes data before authentication checks.
  • The attacker will then extract SharePoint’s MachineKey configuration which includes the ValidationKey
  • From here, attackers will create a payload that appears to come from an authenticated user
  • Once the payloads are accepted, the attacker can now run any arbitrary code, exfiltrate data, install backdoors, or simply modify site content

Impact

Allows attackers to gain unauthenticated Remote Code Execution (RCE) which is essentially full control over the entire server without needing valid credentials.

Mitigation Strategies

  1. Ensure on-premises SharePoint Servers are on a supported version
    1. Microsoft SharePoint Server Subscription Edition
    2. Microsoft SharePoint Server 2019
    3. Microsoft SharePoint Server 2016
  2. Apply the latest patches released by Microsoft
  3. Ensure servers are protected by a reputable EDR solution
  4. Ensure Antimalware Scan Interface (AMSI) is turned on and configured correctly
  5. Rotate SharePoint Server ASP.NET machine keys
  6. Restart IIS on all SharePoint servers

Sources

Contributing Authors

  • Daniel Felzke – Senior Director, Digital Forensics and Incident Response

Dataprise

Dataprise is a national managed service provider that believes that technology should enable our clients to be the absolute best at what they do.

Let’s talk IT.

Request a consultation. Tell us where your offices are and one of our engineers will be in touch within one business day — no sales script, no obligation, just a working conversation about what you’re trying to do.

cyber insurance

"*" indicates required fields

Your Name*