Listen to this Post

Microsoft Rushes Out Emergency Fixes Amidst “ToolShell” Exploits Targeting SharePoint Servers
Microsoft has issued emergency guidance after detecting a wave of active cyberattacks exploiting two dangerous zero-day vulnerabilities in on-premises SharePoint Servers. Tracked as CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771 (CVSS 6.3), these flaws are being chained together in a sophisticated exploit campaign nicknamed “ToolShell.” The attack campaign was detected in the wild on July 18, 2025, with researchers confirming dozens of real-world compromises within hours.
While these vulnerabilities don’t affect SharePoint Online (Microsoft 365), on-prem SharePoint environments are at severe risk. The first and more critical vulnerability (53770) involves deserialization of untrusted data, allowing unauthenticated remote code execution. This means attackers can run malicious code on a vulnerable SharePoint server without any login—a nightmare scenario for organizations.
The bug was discovered by Viettel Cyber Security and reported via Trend Micro’s Zero Day Initiative (ZDI). Microsoft confirmed its active exploitation and issued temporary mitigations while a full security patch is under development. It urges all customers to enable AMSI integration and deploy Microsoft Defender across all SharePoint Server farms.
CVE-2025-53770 is considered a variant of a previously known flaw, CVE-2025-49706, which was addressed in July Patch Tuesday. Microsoft noted that attackers are chaining it with CVE-2025-53771, a path traversal-based spoofing vulnerability, first reported by an anonymous researcher. This combination makes the “ToolShell” exploit highly effective and stealthy, especially since attackers are using stolen machine keys for persistence and lateral movement within corporate networks.
Researchers at Eye Security and Palo Alto Networks highlighted that these attacks escalated rapidly following public Proof-of-Concept demonstrations. Eye Security scanned over 8,000 SharePoint servers globally and found multiple instances of active compromise, primarily during a narrow time window from 18:00 UTC on July 18 to 07:30 UTC on July 19.
The nature of these vulnerabilities makes detection difficult without deep visibility at the endpoint level. Microsoft acknowledges the seriousness of the attack chain and plans to release hardened patches with stronger protections than earlier fixes for related bugs.
What Undercode Say:
The emergence of “ToolShell” marks a pivotal moment in the cybersecurity landscape for enterprise collaboration tools. SharePoint, widely used in corporate environments to manage internal data, has now become the centerpiece of a sophisticated, multi-pronged cyber offensive. The attackers are not merely opportunistic—they’re coordinated, stealthy, and clearly targeting high-value systems with precision timing.
The use of unauthenticated RCE through deserialization, combined with spoofing via path traversal, creates a nearly perfect exploitation chain. These are not just isolated bugs; they reflect a broader architectural weakness in how SharePoint handles input validation and data trust models. Organizations still relying on on-premises deployments—often for regulatory or internal policy reasons—are now forced to reconsider the long-term viability of such infrastructure.
Furthermore, this campaign is notable for its speed and scale. From the moment the exploit was demonstrated publicly, it took less than 72 hours for attackers to compromise systems worldwide. This shows that threat actors are actively monitoring the security research space, ready to weaponize PoCs almost in real-time.
Another concerning aspect is the attackers’ use of machine key theft to persist on systems and perform lateral movement, which implies they are not just infiltrating but attempting to own entire environments. Once inside, the potential for data exfiltration, ransomware deployment, or even long-term espionage increases dramatically.
This is a loud wake-up call for IT administrators: patching cycles must evolve. Waiting for scheduled patch releases is no longer safe. Organizations must now treat vulnerability management as a crisis response activity—with real-time monitoring, emergency mitigation deployment, and forensic analysis becoming standard.
Lastly, it highlights Microsoft’s challenge in balancing legacy support with modern security demands. SharePoint Online remains untouched, which emphasizes the security and maintenance benefits of cloud-native platforms. As hybrid environments persist, those still relying on older, on-prem models may need to reevaluate their threat posture and transition timelines.
🔍 Fact Checker Results:
✅ CVE-2025-53770 is actively exploited in the wild, confirmed by Microsoft and security researchers.
✅ Exploits affect only on-premises SharePoint Servers, not SharePoint Online (Microsoft 365).
✅ The exploit chain “ToolShell” is linked to vulnerabilities CVE-2025-49704, 49706, 53770, and 53771.
📊 Prediction:
As the ToolShell exploit continues to evolve, expect to see ransomware groups and state-backed APTs integrate this chain into their attack playbooks. If left unpatched, this could become one of 2025’s most damaging enterprise vulnerabilities. We predict that within the next two months, Microsoft will release a comprehensive patch—but many enterprises may suffer breaches before deploying it. Expect also a wave of third-party vulnerability scanners to include ToolShell checks as a default in corporate audits.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




