ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

SharePoint ‘ToolShell’ Vulnerabilities Exploited by Chinese Hackers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
Full article657 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has confirmed three Chinese-based threat groups have been actively exploiting CVE-2025-53770 and CVE-2025-53771, two critical and high-severity vulnerabilities in internet-facing SharePoint servers.

The chained exploitation of these two bugs has been dubbed ‘ToolShell’ by the cybersecurity community.

In a new blog posted on July 22, Microsoft Threat Intelligence confirmed that these groups include Linen Typhoon and Violet Typhoon, two China-based advanced persistent threat (APT) groups and Storm-2603, another China-based threat actor whose motivations and identity are unclear at this time.

Who is Behind Linen Typhoon, Violet Typhoon and Storm-2603

Linen Typhoon (APT27) is a Chinese state-backed actor that has been active since at least 2010. It typically targets foreign embassies to collect data on government, defense, technology and human rights organizations, using techniques such as drive-by compromises and existing exploits to compromise organizations.

The group is also known by many other names, including Bronze Union, Circle Typhoon, Budworm, Emissary Panda, Earth Smilodon, GreedyTaotie, Iron Taurus, Iron Tiger, Lucky Mouse and Red Phoenix.

In March 2025, the US indicted and charged two Chinese nationals believed to be operating within the APT27 group. The two individuals were accused of hacking several US companies, institutions and municipalities for profit, causing millions of dollars’ worth of damages.

Violet Typhoon (APT31) is a Chinese state-backed actor that has been active since at least 2012.

Also known as Bronze Vinewood, Judgment Panda, Red keres and Zirconium, Violet Typhoon has minimal overlaps with another group with unclear attribution, tracked as Storm-0558.

Violet Typhoon typically specializes in intellectual property theft, focusing on data and projects that make a particular organization competitive in its field. The group primarily targets former government and military personnel, non-governmental organizations (NGOs), think tanks, higher education institutions, digital and print media, as well as financial and health-related sectors in the US, Europe and East Asia.

Violet Typhoon persistently scans for vulnerabilities in the exposed web infrastructure of target organizations, exploiting discovered weaknesses to install web shells.

Finally, while Microsoft assessed “with medium confidence” that Storm-2603 is a China-based threat actor, the tech giant’s threat intelligence team has not yet identified any links between the group and other known Chinese threat actors.

“Microsoft tracks this threat actor in association with attempts to steal MachineKeys via the on-premises SharePoint vulnerabilities,” said the Microsoft Threat Intelligence team.

Additionally, while the company has observed this threat actor deploying Warlock and Lockbit ransomware in the past, it is currently unable to confidently assess the threat actor’s objectives.

Aligned with Previous Attribution

This new Microsoft assessment aligns with a previous estimate from Google Cloud-owned Mandiant.

Earlier on July 22, Charles Carmakal, CTO of Mandiant Consulting at Google Cloud, commented: “We assess that at least one of the actors responsible for this early exploitation is a China-nexus threat actor.”

Speaking to Infosecurity, Lorri Janssen-Anessi, director of external cyber assessments at BlueVoyant, highlighted that this attribution to Chinese nation-state hacking groups reinforces that the 'ToolShell' exploitation campaign is "more than opportunistic exploitation."

"It is more likely potentially part of a broader strategic campaign aimed at gaining initial access, establishing persistence, and attempting to exfiltrate sensitive intelligence data from high-value targets across government, defence, academia and NGOs. This is yet another reminder that if you are running unpatched, internet-facing systems – especially legacy collaboration platforms – you are not just a potential target, you are likely already in the crosshairs," she added.

Mandiant's Carmakal also emphasized the importance for cybersecurity professionals and potential victims to recognize that multiple actors are likely actively exploiting these vulnerabilities.

“We fully anticipate that this trend will continue, as various other threat actors, driven by diverse motivations, will leverage this exploit as well,” he said.

This statement aligns with Microsoft’s assessment: “Investigations into other actors also using these exploits are still ongoing. With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/sharepoint-toolshell-chinese/