Overview

Microsoft has issued emergency out-of-band security updates for CVE-2025-53770 (remote code execution (RCE); CVSS 9.8) and CVE-2025-53771 (spoofing), two zero-day vulnerabilities affecting on-premises SharePoint Servers. These vulnerabilities are being actively exploited in the wild as part of a sophisticated campaign dubbed ToolShell, first demonstrated during Pwn2Own Berlin 2025. 

The exploitation chain bypasses earlier patches (CVE-2025-49704 and CVE-2025-49706) and enables unauthenticated RCE. Microsoft has attributed the campaign to multiple China-nexus threat actors, including Linen Typhoon, Violet Typhoon, and Storm-2603, with investigations still ongoing. 

More than 54 organisations across North America, Western Europe, the Middle East, and Africa have been impacted so far, including government entities, engineering firms, telecommunications providers, and software vendors. A public proof-of-concept (PoC) exploit was released this week, further increasing the likelihood of widespread exploitation. In response, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-53770 to its Known Exploited Vulnerabilities (KEV) catalogue, mandating urgent action across federal networks. 

Impact

The successful exploitation of CVE-2025-53770 allows unauthenticated RCE via unsafe deserialization, granting attackers full access to SharePoint environments, file systems, internal configurations, and integrated Microsoft services. This enables lateral movement, data theft, and long-term persistence across enterprise environments.  

The release of a public PoC exploit and observed use by multiple Chinese state-linked threat actors significantly heightens the threat. With an updated EPSS score of 3.04% (86th percentile), exploitation activity is expected to grow rapidly, particularly as ToolShell becomes more accessible to other actors. 

Organisations running on-prem SharePoint 2016, 2019, or Subscription Edition are strongly advised to apply Microsoft’s emergency patches and begin internal investigations for signs of compromise. 

Technical Breakdown

  • CVE-2025-53770 (CVSS 9.8) is an RCE vulnerability caused by the unsafe deserialization of untrusted data in on-premises SharePoint Server. Exploitation allows unauthenticated attackers to execute arbitrary code via crafted HTTP POST requests. 
  • Attackers use PowerShell commands to deploy a custom web shell (spinstall0.aspx) designed to extract cryptographic machine keys (ValidationKey and DecryptionKey), enabling the forgery of ViewState payloads and persistent access across SharePoint environments.
  • CVE-2025-53771 (CVSS 7.1) is a spoofing vulnerability involving improper path restrictions. When chained with CVE-2025-53770 or prior flaws (e.g. CVE-2025-49706), it facilitates initial access or privilege escalation.
  • Variants of CVE-2025-49704 and CVE-2025-49706: These CVEs represent bypass techniques for Microsoft’s July Patch Tuesday fixes and include more robust protections in the emergency update.
  • Observed tradecraft includes:

o Deployment of stealthy, in-memory .NET modules 

o Use of password-protected ASPX web shells 

o Exploitation activity from IPs linked to prior Ivanti EPMM attacks 

o Targeted, selective compromises across telecoms, governments, critical infrastructure, and engineering sectors

Quorum Cyber’s Threat Intelligence Assessment

On-premises SharePoint servers remain a high-value target due to their tight integration with Microsoft services. The renewed exploitation of ToolShell variants highlights continued threat actor focus on Microsoft collaboration infrastructure, particularly in environments where patching lags behind cloud protections. 

Recommendations

Apply Emergency Security Updates 

  • Install the emergency out-of-band patches for: 
  • SharePoint Server Subscription Edition – KB5002768 
  • SharePoint Server 2019 – KB5002754 (Core), KB5002753 (Language Pack) 
  • SharePoint Server 2016 – KB5002760 (Enterprise), KB5002759 (Language Pack) 
  • Only supported SharePoint versions are patched. Legacy or unpatched systems remain vulnerable

Rotate SharePoint ASP.NET Machine Keys 

  • Required after patching or enabling AMSI 

Hunt for Indicators of Compromise (IOCs) 

  • Scan for presence of malicious web shells 
  • Review IIS logs 
  • Investigate activity from suspicious IPs 

Remove Public Exposure 

  • Temporarily remove internet exposure of SharePoint servers not yet patched 
  • Deploy network segmentation and WAF controls to limit access during patching window 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content