Skip to content

Defense Digests

Microsoft SharePoint Zero-Day Vulnerability “ToolShell” Actively Exploits On-Premises Servers

Dataprise Defense Digest 550x550 square 81b9c004fda6a6de80ab2a0e7f7c7938 46aw13uh8spc

Table of content

Vulnerabilities:

CVE-2025-53770 – 9.8 CRITICAL

CVE-2025-53771 – 6.5 MEDIUM

Executive Summary

Two zero-day vulnerabilities affecting on-premises Microsoft SharePoint servers have been recently reported with a CVSS rating of 9.8 and 6.5.  Microsoft released out-of-band patches for these vulnerabilities on 07/21/2025.  Unpatched servers are susceptible to an attack known as “ToolShell” which allows remote code execution on servers.  It is important to note that SharePoint Online in Microsoft 365 is NOT impacted.  The earliest reports of compromise are from 07/07/2025 and organizations are encouraged to apply these patches as soon as possible.

Details

  • On an unpatched server, attackers will send a malicious HTTP request to a process that serializes data before authentication checks.
  • The attacker will then extract SharePoint’s MachineKey configuration which includes the ValidationKey
  • From here, attackers will create a payload that appears to come from an authenticated user
  • Once the payloads are accepted, the attacker can now run any arbitrary code, exfiltrate data, install backdoors, or simply modify site content

Impact

Allows attackers to gain unauthenticated Remote Code Execution (RCE) which is essentially full control over the entire server without needing valid credentials.

Mitigation Strategies

  1. Ensure on-premises SharePoint Servers are on a supported version
    1. Microsoft SharePoint Server Subscription Edition
    2. Microsoft SharePoint Server 2019
    3. Microsoft SharePoint Server 2016
  2. Apply the latest patches released by Microsoft
  3. Ensure servers are protected by a reputable EDR solution
  4. Ensure Antimalware Scan Interface (AMSI) is turned on and configured correctly
  5. Rotate SharePoint Server ASP.NET machine keys
  6. Restart IIS on all SharePoint servers

Sources

Contributing Authors

  • Daniel Felzke – Senior Director, Digital Forensics and Incident Response

Recent Tweets

INSIGHTS

Learn about the latest threats and vulnerabilities with our D3 alerts.

Subscribe to get real-time notifications when a new Dataprise Defense Digest is published.