Listen to this Post

Microsoft in Crisis Mode After ToolShell SharePoint Flaws Exposed to Global Attacks
A new wave of cyberattacks is targeting Microsoft SharePoint servers worldwide, following the public disclosure of two critical zero-day vulnerabilities — CVE-2025-53770 and CVE-2025-53771 — now being actively exploited in the wild. Labeled as “ToolShell,” these flaws pose a severe threat to on-premises SharePoint deployments, allowing unauthenticated attackers to execute arbitrary code remotely, hijack servers, and move laterally across networks. With a CVSS severity score of 9.8, CVE-2025-53770 has been added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, forcing federal agencies to take immediate action.
🔍 the Original Report
This week, Microsoft released emergency updates for two high-severity flaws in SharePoint Server: CVE-2025-53770 and CVE-2025-53771. Both vulnerabilities, only affecting on-premise servers, can be chained together to enable unauthenticated remote code execution (RCE). The issue stems from unsafe deserialization of untrusted data, enabling attackers to execute code over the network. The vulnerability was discovered by Viettel Cyber Security and reported via Trend Micro’s Zero Day Initiative (ZDI).
CVE-2025-53770, rated 9.8 on the CVSS scale, is already under active exploitation. Microsoft confirmed it’s a variant of a previous vulnerability, CVE-2025-49706, which was partially addressed in the July 2025 Patch Tuesday rollout. The company has urged customers to implement mitigations and enable AMSI integration along with Microsoft Defender for enhanced protection.
Security firms Eye Security and Palo Alto Networks observed real-world exploitation starting July 18, 2025, targeting over 8,000 SharePoint instances. Their scans revealed dozens of compromised systems, indicating widespread global exposure. The attackers appear to use stolen machine keys for persistence and lateral movement, rendering detection extremely difficult without advanced endpoint visibility.
CISA has officially ordered all U.S. Federal Civilian Executive Branch (FCEB) agencies to patch the flaws by July 21, 2025, under Binding Operational Directive (BOD) 22-01. Experts advise private enterprises to follow suit, stressing that SharePoint Online is not impacted.
🧠 What Undercode Say:
The ToolShell vulnerability chain represents one of the most dangerous SharePoint exploits disclosed in recent years — not only due to its high CVSS score but also its operational sophistication and global reach. The fact that attackers are chaining vulnerabilities for pre-auth RCE is a serious red flag, showing just how valuable on-prem SharePoint infrastructure remains for cyber espionage, ransomware, or state-backed operations.
What makes ToolShell particularly insidious is its use of object deserialization, a known attack vector in enterprise environments that often flies under the radar. When paired with stolen machine keys, attackers can effectively cloak their presence, bypass authentication, and establish long-term persistence.
This campaign also highlights how traditional patch cycles are no longer sufficient. Microsoft was caught in the middle of preparing a full patch when active exploitation surged. Their interim recommendations — such as enabling AMSI and Defender — are useful but not foolproof. Organizations without proper endpoint detection and response (EDR) tools or skilled security teams could already be compromised without knowing it.
From a threat intel standpoint, the rapid coordination of disclosure (via Trend Micro ZDI), discovery (Eye Security’s scanning), and action (CISA’s mandate) shows a more agile cybersecurity ecosystem. However, this agility is not universal. Thousands of SharePoint deployments — especially in small and mid-sized enterprises — may remain unpatched for weeks or even months.
This event serves as a brutal reminder: if you’re running on-prem infrastructure in 2025 without a real-time patch management and threat detection system, you are a sitting duck. Public cloud services like SharePoint Online are increasingly attractive not only for features but for the resilience they offer against these types of exploits.
Enterprises that haven’t yet migrated to Microsoft 365 may want to reassess the cost of staying on-prem. The “savings” of local hosting don’t look so appealing when they come bundled with ransomware threats, regulatory exposure, and the constant risk of zero-day exploitation.
✅ Fact Checker Results:
CVE-2025-53770 has a confirmed CVSS score of 9.8 and is actively exploited (✅ Verified).
Only on-premises Microsoft SharePoint Servers are affected — SharePoint Online remains safe (✅ Verified).
Attackers are using stolen machine keys and chaining vulnerabilities to escalate attacks (✅ Verified).
📊 Prediction:
We expect more ToolShell-style exploitation chains to emerge in Q3–Q4 2025 targeting legacy enterprise software, especially Microsoft-hosted services not yet migrated to the cloud. As attackers refine their methods, AI-driven lateral movement detection will become a must-have, and federal agencies failing to patch by CISA’s deadline could face disruptive intrusions or even public breaches before year-end.
Organizations not already compromised should assume they’re next in line — and act accordingly.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




