Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Microsoft Fix Targets SharePoint Zero-Day Attacks - News Directory 3

Microsoft Fix Targets SharePoint Zero-Day Attacks

July 26, 2025 Lisa Park Tech
News Context
At a glance
Original source: krebsonsecurity.com

SharePoint Under Siege: “ToolShell” Backdoor ‍Exploits zero-Day Flaw, CISA Warns

Table of Contents

  • SharePoint Under Siege: “ToolShell” Backdoor ‍Exploits zero-Day Flaw, CISA Warns
    • the “toolshell” Threat: Unauthenticated Remote Access
    • Eye⁤ Security Uncovers⁤ Widespread Exploitation
    • microsoft’s Response and Affected Versions
    • CISA’s Recommended Mitigation ⁤Strategies
    • The Exploit Chain: A Complex Vulnerability Landscape

Microsoft SharePoint servers are facing a critical security threat⁣ as attackers are actively exploiting a zero-day vulnerability, retrofitting compromised systems with a backdoor dubbed “ToolShell.” the Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning, urging organizations to take immediate action beyond patching to mitigate the risks.

the “toolshell” Threat: Unauthenticated Remote Access

The newly discovered flaw‍ allows attackers to gain unauthenticated, remote access to vulnerable SharePoint servers. Once ⁤inside,⁤ “toolshell” provides attackers with complete control, enabling them to access all SharePoint content, including file systems and internal⁣ configurations, and execute code directly over the network. This level of access poses a ‍severe risk to sensitive data and organizational integrity.

Eye⁤ Security Uncovers⁤ Widespread Exploitation

Researchers at Eye Security were the first to identify the large-scale exploitation of this SharePoint vulnerability on july 18, 2025. Their investigation revealed dozens ‍of servers already ⁢compromised and⁣ infected with the⁣ “ToolShell” backdoor. In a detailed blog post, eye Security highlighted that the primary ⁣objective of these attacks appears⁣ to be the theft of SharePoint server ASP.NET machine keys.

“These ⁣keys can⁤ be used to facilitate further ‍attacks, ⁣even at a later date,” warned Eye security.”It is critical that affected servers rotate SharePoint ⁤server ASP.NET machine ⁤keys and restart IIS⁤ on all SharePoint servers. patching alone is not enough. We strongly advise defenders not to wait for a vendor fix before taking action. ⁤This threat is already operational and spreading rapidly.”

microsoft’s Response and Affected Versions

Microsoft has acknowledged the severity of the situation and has ‍issued ⁤updates for SharePoint Server Subscription Edition and SharePoint ⁣Server 2019. However, the company⁢ is⁢ still working on providing patches ⁣for ⁣supported⁤ versions of SharePoint 2019 and SharePoint 2016.

CISA’s Recommended Mitigation ⁤Strategies

In response to ‍the active exploitation, CISA has provided a‍ set of crucial recommendations for vulnerable organizations:

Enable Anti-Malware Scan Interface (AMSI): Organizations should ensure AMSI ⁣is enabled within their SharePoint environments.
deploy Microsoft Defender AV: Implementing Microsoft Defender Antivirus⁣ on⁤ all SharePoint servers is strongly advised.* Isolate affected Systems: Until an official patch is available,affected products ‍should be disconnected from the ⁢public-facing internet⁣ to prevent further ⁤compromise.

The Exploit Chain: A Complex Vulnerability Landscape

security firm⁣ Rapid7 has⁤ shed ⁣further light on the technical details, noting that Microsoft ⁢has linked CVE-2025-53770, the current zero-day, to a⁢ previously patched vulnerability, CVE-2025-49704. This earlier vulnerability was part of an ⁣exploit chain demonstrated at the Pwn2own hacking competition in May 2025. That ⁤exploit chain also leveraged a second SharePoint weakness,⁣ CVE-2025-49706, which Microsoft had attempted to fix in a previous Patch‍ Tuesday update but was apparently ⁣unsuccessful.

Microsoft has also released a patch for a related SharePoint vulnerability, CVE-2025-53771. While ther are ⁤currently no signs of active attacks targeting CVE-2025-53771, Microsoft states that this patch offers more robust protection⁤ than the update for CVE-2025-49706.

This is a rapidly developing story, and organizations are urged to stay informed and implement the recommended security measures without delay.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

More on this

  • Berck and Calais Face Off in France’s Favorite Beach Final
  • WhatsApp Brings Restricted Chat to iOS to Block Linked Devices

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com