Microsoft Fix Targets SharePoint Zero-Day Attacks
Microsoft SharePoint servers are facing a critical security threat as attackers are actively exploiting a zero-day vulnerability, retrofitting compromised systems with a backdoor dubbed “ToolShell.” the Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning, urging organizations to take immediate action beyond patching to mitigate the risks.
the “toolshell” Threat: Unauthenticated Remote Access
The newly discovered flaw allows attackers to gain unauthenticated, remote access to vulnerable SharePoint servers. Once inside, “toolshell” provides attackers with complete control, enabling them to access all SharePoint content, including file systems and internal configurations, and execute code directly over the network. This level of access poses a severe risk to sensitive data and organizational integrity.
Eye Security Uncovers Widespread Exploitation
Researchers at Eye Security were the first to identify the large-scale exploitation of this SharePoint vulnerability on july 18, 2025. Their investigation revealed dozens of servers already compromised and infected with the “ToolShell” backdoor. In a detailed blog post, eye Security highlighted that the primary objective of these attacks appears to be the theft of SharePoint server ASP.NET machine keys.
“These keys can be used to facilitate further attacks, even at a later date,” warned Eye security.”It is critical that affected servers rotate SharePoint server ASP.NET machine keys and restart IIS on all SharePoint servers. patching alone is not enough. We strongly advise defenders not to wait for a vendor fix before taking action. This threat is already operational and spreading rapidly.”
microsoft’s Response and Affected Versions
Microsoft has acknowledged the severity of the situation and has issued updates for SharePoint Server Subscription Edition and SharePoint Server 2019. However, the company is still working on providing patches for supported versions of SharePoint 2019 and SharePoint 2016.
CISA’s Recommended Mitigation Strategies
In response to the active exploitation, CISA has provided a set of crucial recommendations for vulnerable organizations:
Enable Anti-Malware Scan Interface (AMSI): Organizations should ensure AMSI is enabled within their SharePoint environments.
deploy Microsoft Defender AV: Implementing Microsoft Defender Antivirus on all SharePoint servers is strongly advised.* Isolate affected Systems: Until an official patch is available,affected products should be disconnected from the public-facing internet to prevent further compromise.
The Exploit Chain: A Complex Vulnerability Landscape
security firm Rapid7 has shed further light on the technical details, noting that Microsoft has linked CVE-2025-53770, the current zero-day, to a previously patched vulnerability, CVE-2025-49704. This earlier vulnerability was part of an exploit chain demonstrated at the Pwn2own hacking competition in May 2025. That exploit chain also leveraged a second SharePoint weakness, CVE-2025-49706, which Microsoft had attempted to fix in a previous Patch Tuesday update but was apparently unsuccessful.
Microsoft has also released a patch for a related SharePoint vulnerability, CVE-2025-53771. While ther are currently no signs of active attacks targeting CVE-2025-53771, Microsoft states that this patch offers more robust protection than the update for CVE-2025-49706.
This is a rapidly developing story, and organizations are urged to stay informed and implement the recommended security measures without delay.
