ZeroHour
Recorded Futurepublished ()ingested Insikt Group®

ToolShell Exploit: Critical SharePoint Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-49704
+1 in the same advisory: …49706
Authenticated Code Injection RCE in Microsoft SharePoint

CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented.

Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers.

8.8
group max
100% KEV ransomware
  • Microsoft SharePoint CISA lists 'Microsoft SharePoint' without enumerating specific version ranges; the CISA KEV guidance targets on-premises SharePoint Server, calling out SharePoi
masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments…
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)

Indicators of compromiseAll →

TypeIndicatorContext
domainasp.netpayload has been identified that allows adversaries to leak ASP.NET machine keys directly from memory without leaving behind st
sha25630955794792a7ce045660bb1e1917eef36f1d5865891b8110bf982382b305b27ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514 30955794792a7ce045660bb1e1917eef36f1d5865891b8110bf982382b305b27 8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd09161292
sha2563461da3a2ddcced4a00f87dcd7650af48f97998a3ac9ca649d7ef3b7332bd997lable on Recorded Future’s public sandbox: File Name SHA256 3461da3a2ddcced4a00f87dcd7650af48f97998a3ac9ca649d7ef3b7332bd997 Background and first exploitation chain Previously, cyberse
sha2568d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2794792a7ce045660bb1e1917eef36f1d5865891b8110bf982382b305b27 8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2 Insikt Group®’s mitigation guidance is that, regardless of
sha25692bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514lable on Recorded Future’s public sandbox: File Name SHA256 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514 30955794792a7ce045660bb1e1917eef36f1d5865891b8110bf982382b3
Full article1,256 words · extracted from recordedfuture.com · click to collapse

A zero-day exploit chain called "ToolShell" is actively being used to target on-premises Microsoft SharePoint servers worldwide, potentially affecting thousands of organizations. The attack leverages two critical vulnerabilities (CVE-2025-53770 and CVE-2025-53771) to achieve remote code execution and steal cryptographic keys, giving attackers persistent access even after organizations apply patches.

These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 has not been impacted.

Read on to understand the ToolShell threat and how to defend against it with hunting packages, including Nuclei and YARA rules, from Recorded Future.

The latest Tactics, Techniques, and Procedures (TTPs)

On July 23, 2025, researchers at LeakIX shared details that adversaries have swiftly evolved their TTPs to be stealthier and eliminate the reliance on .ASPX web shells. A new in-memory ToolShell payload has been identified that allows adversaries to leak ASP.NET machine keys directly from memory without leaving behind static artifacts. Adversaries no longer need to rely on static file-based indicators, making traditional detection methods such as checking for web shells unreliable. This new payload directly extracts sensitive machine keys and system information from memory and exfiltrates the data immediately via a single HTTP request, enabling rapid and stealthy compromise.

The Insikt Group® used Recorded Future’s Malware Intelligence feature to identify this new in-memory ToolShell payload and created a YARA rule capable of detecting the in-memory ToolShell payload.

This new ToolShell payload is available on Recorded Future’s public sandbox:

File Name

SHA256

3461da3a2ddcced4a00f87dcd7650af48f97998a3ac9ca649d7ef3b7332bd997

Background and first exploitation chain

Previously, cybersecurity researchers at Eye Security on July 18 published details of an ongoing mass exploitation campaign targeting internet-exposed on-premises SharePoint servers.

The ToolShell exploit chain combines two critical unauthenticated remote code execution vulnerabilities that specifically target on-premises SharePoint servers configured with hybrid Active Directory Federation Services (ADFS). These vulnerabilities are essentially sophisticated bypasses of earlier security fixes, demonstrating how threat actors continue to evolve their techniques in response to security efforts.

ToolShell represents an evolution of an exploit chain first demonstrated at Pwn2Own Berlin in May 2025, where security researchers combined an authentication-bypass vulnerability (CVE-2025-49706) with a remote code execution flaw (CVE-2025-49704). The current campaign uses:

  • CVE-2025-53770, which exploits insecure deserialization to conduct remote code execution
  • CVE-2025-53771, which bypasses authentication controls via path traversal

What makes this attack particularly dangerous is that successful exploitation provides threat actors with SharePoint's ValidationKey and DecryptionKey—cryptographic keys that enable persistent access to compromised servers even after security patches are applied.

Scale and impact

Recorded Future's Attack Surface Intelligence proactively scanned our customer base and confirmed that nearly 5% of organizations scanned with SharePoint servers were still susceptible to CVE-2025-53770. We immediately deployed alerts to affected customers within hours of implementing detection capabilities—giving them critical advance warning before the vulnerability gained widespread media attention.

Bloomberg reported on July 23 that there were over 400 victims of the exploitation campaign targeting on-premises Microsoft SharePoint servers.

Using Recorded Future's Malware Intelligence to identify and neutralize the ToolShell threat

Despite the updated TTP which allows attackers to no longer rely on static file-based indicators to leak ASP.NET machine keys, the Insikt Group® used the Recorded Future’s Malware Intelligence feature to identify several malicious artifacts tied to prior iteration of ToolShell exploitation campaign. These samples provide further insight into the exploit chain’s post-compromise behavior, particularly around key extraction, persistence, and web shell deployment.

Those previous static malware artifacts are all available on Recorded Future’s public sandbox:

File Name

SHA256

92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514

30955794792a7ce045660bb1e1917eef36f1d5865891b8110bf982382b305b27

8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2

Insikt Group®’s mitigation guidance is that, regardless of the presence or absence of suspicious files, organizations must proactively rotate all cryptographic keys.

With Malware Intelligence, Recorded Future customers can use natural language search to quickly surface these malware samples and any others that are related to the exploitation of the SharePoint CVEs.

Figure 1: Malware Hunting Query for Samples Related to CVE-2025-53770 using Malware Intelligence (Source: Recorded Future)

Analysts can easily pivot to associated Intelligence Cards® for malware associations, sandbox results, Insikt Group® research, and detections from customers’ security tools.

Figure 2: SHA256 Hash Intelligence Card® for a ToolShell malware sample, “spinstall0.aspx” (Source: Recorded Future)

Enable proactive defense with Recorded Future

Recorded Future customers can use the following tools and strategies to mitigate risk:

  • Get the Insikt Group® Nuclei template. Download our YAML file to access a Nuclei template for CVE-2025-53770. The template sends a GET request to SharePoint Server’s "/_vti_pvt/service.cnf" endpoint, extracts the "vti_extenderversion" build number, and checks to see if it’s within the documented vulnerable ranges.
  • Use the latest YARA rule. Download our .yar file to access a YARA rule capable of detecting the in-memory ToolShell payload.
  • Leverage our Attack Surface Intelligence (ASI) Module. While the new ToolShell TTP does not rely on .ASPX web shells, Recorded Future previously released a signature on July 19 to detect the persistent web shell, “spinstall0.aspx,” indicating the presence of a ToolShell backdoor implant. On July 20, we released a signature to detect vulnerable SharePoint server versions to CVE-2025-53770. Since then, all new ASI scans will detect those signatures. Customers can also run an on-demand scan anytime. (Note: Recorded Future has reached out to the customers with confirmed signature detections in their ASI scans.)

Figure 3: Attack Intelligence Signatures to detect CVE-2025-53770 and web shell “spinstall0.aspx” (Source: Recorded Future)

  • Use our Vulnerability Intelligence Module. Get helpful context on CVE-2025-53770 to aid in patching and prioritization discussions.

Figure 4: Vulnerability Intelligence Card® for CVE-2025-53770 in Recorded Future (Source: Recorded Future)

Microsoft’s guidance to protect your organization

Based on Microsoft's guidance, organizations should take these steps immediately:

For SharePoint 2019 and later:

For SharePoint 2016:

For all versions:

  • Conduct scanning for IP addresses:
    • 104.238.159[.]149
    • 131.226.2[.]6
    • 134.199.202[.]205
    • 188.130.206[.]168

Find the complete Microsoft advisory here.

  • CISA additionally recommends conducting scanning for IP addresses 96.9.125[.]147, 104.238.159[.]149, and 107.191.58[.]76 particularly between July 18-19, 2025.
  • Eye Security also recommends scanning for the following IP addresses, observed after July 21:
    • 34.72.225[.]196
    • 34.121.207[.]116
    • 45.77.155[.]170
    • 45.191.66[.]77
    • 64.176.50[.]109
    • 141.164.60[.]10
    • 206.166.251[.]228

Who’s behind the attack, and what will happen next?

On July 22, 2025, Microsoft disclosed that at least three Chinese state-sponsored threat actors have been exploiting the ToolShell zero-day since at least July 7, 2025. These are Linen Typhoon (which historically overlaps with TAG-67 as tracked by Recorded Future), Violet Typhoon (which historically overlaps with RedBravo as tracked by Recorded Future), and Storm-2603. The actors exploited CVE-2025-49704 (RCE) and CVE-2025-49706 (spoofing) to compromise on-premises SharePoint servers, with additional vulnerabilities CVE-2025-53770 and CVE-2025-53771 affecting previously patched systems.

Linen Typhoon has been known to exploit zero-day and n-day vulnerabilities for initial access, and to exploit known vulnerabilities years after they were initially disclosed. For example, in 2021, the threat group exploited a zero-day vulnerability in Zoho AdSelf Service Plus.

Chinese threat groups have increasingly adopted internet-facing appliance exploitation as a scalable initial access strategy, allowing them to establish footholds across numerous organizations simultaneously.

Insikt Group® assesses at this stage that it is likely that multiple other threat groups beyond Linen Typhoon, Violet Typhoon, and Storm-2603 will actively seek to exploit on-premise SharePoint instances, especially following the public release of proof-of-concept exploit code.

Our intelligence indicates that the current campaign represents an early phase of what will likely become a prolonged exploitation effort. We will continue to monitor and analyze the threat in real time and will share any updates on intelligence and mitigation strategies as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/toolshell-exploit-chain-thousands-sharepoint-servers-risk