US CISA Adds Critical Microsoft SharePoint Flaws to Known Exploited Vulnerabilities Catalog

Listen to this Post

Featured Image
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These flaws are under active exploitation, posing a significant risk to organizations relying on SharePoint. Here’s a breakdown of the vulnerabilities and the subsequent actions taken by both Microsoft and CISA.

The Vulnerabilities at a Glance

Microsoft has issued a warning about a high-risk zero-day vulnerability, identified as CVE-2025-53770. With a CVSS score of 9.8, this vulnerability is being actively exploited. It stems from a deserialization of untrusted data in the on-premises Microsoft SharePoint Server, which allows unauthorized attackers to execute code over a network. This critical flaw was discovered by Viettel Cyber Security and reported through Trend Micro’s ZDI.

Additionally, Microsoft revealed that CVE-2025-53770 is related to a previously identified spoofing flaw, CVE-2025-49706, with a lower CVSS score of 6.3. The patch addressing CVE-2025-49706 was included in the July 2025 Patch Tuesday updates. However, despite this fix, attackers have found a way to exploit both vulnerabilities in tandem, often leveraging a combined attack chain called “ToolShell.”

The Chain of Attacks

Between July 17 and 19, 2025, cybersecurity researchers from SentinelOne observed three distinct waves of exploitation targeting these vulnerabilities. Each wave exhibited different methods, but all focused on maintaining persistent access and compromising high-value SharePoint deployments:

First Wave (July 18): Attackers used PowerShell to deploy a payload (spinstall0.aspx) to the SharePoint LAYOUTS directory, focusing on harvesting MachineKey values crucial for forging authentication tokens. This tactic enables attackers to maintain access in environments using load-balancing techniques.

Second Wave (July 19): The attackers repeated the first payload deployment, but altered the target directory path to target another SharePoint version. Again, the focus was on extracting cryptographic secrets rather than executing commands.

“No Shell” Cluster (July 17–18): This stealthiest wave involved in-memory .NET module execution, where the attackers executed payloads without writing files to disk. The payloads were executed dynamically using PowerShell or .NET reflection, making detection incredibly difficult. This technique suggests a highly skilled threat actor, possibly a nation-state, prioritizing stealth over immediate system control.

These attacks appear to be strategically focused on persistence and credential harvesting rather than immediate exploitation or system control, indicating a methodical and long-term approach.

What Undercode Says:

This recent exploitation chain highlights a growing trend of advanced persistent threats (APTs) targeting unpatched vulnerabilities within widely used systems like SharePoint. While Microsoft has patched one of the vulnerabilities, the simultaneous exploitation of CVE-2025-49706 and CVE-2025-53770 showcases how attackers can combine multiple flaws to maintain persistent access.

Given that these vulnerabilities are being actively exploited, it’s crucial that both federal agencies and private organizations prioritize patching these flaws. The CISA’s directive for federal agencies to fix the vulnerabilities by July 23, 2025, emphasizes the importance of rapid remediation in protecting sensitive infrastructure.

Furthermore, the involvement of nation-state actors, such as those suspected to be linked to China, underscores the growing geopolitical stakes in cybersecurity. Organizations should not only focus on technical patching but also bolster their monitoring and response capabilities to detect and mitigate such stealthy intrusions.

Finally, as the nature of these attacks becomes increasingly sophisticated, it’s essential for organizations to adopt a proactive stance, continuously monitor their networks, and stay up-to-date with vulnerability catalogs like the CISA KEV list. Ignoring these warnings could lead to catastrophic breaches, given how these attacks are evolving.

🔍 Fact Checker Results

  1. The vulnerability CVE-2025-53770 has a CVSS score of 9.8, confirming its high severity.
  2. The ToolShell attack chain accurately describes multiple exploitation waves observed by SentinelOne.
  3. The CISA directive for federal agencies to patch these vulnerabilities by July 23, 2025 is confirmed as a critical deadline.

📊 Prediction

Given the targeted nature of these attacks and their focus on long-term persistence, it’s highly likely that future exploitations will see more coordinated attempts to bypass detection through advanced evasion techniques. Additionally, we can expect more nation-state actors to adopt similar methodologies for credential harvesting, especially targeting high-value infrastructure in both the public and private sectors. The next few months will likely see a surge in cybersecurity efforts to contain these vulnerabilities, including patch updates and threat intelligence sharing initiatives.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin