TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Microsoft Patches SharePoint Bug, Leaves 2016 Servers Exposed

Paul Balo by Paul Balo
July 21, 2025
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Microsoft has moved fast to blunt an active exploitation wave targeting on‑premises SharePoint Server, rolling out out‑of‑band fixes for two freshly numbered zero‑days—CVE‑2025‑53770 and the closely...
  • The company released security updates late on 19 July for SharePoint Server Subscription Edition (KB 5002768) and SharePoint 2019 (KB 5002754), but confirmed that SharePoint 2016 remains unpatched while the update “finishes validation.” ToolShell...
  • An unauthenticated attacker can send one crafted SOAP request to a publicly exposed server and immediately run arbitrary code as the SharePoint service account—no credentials, no...

Microsoft has moved fast to blunt an active exploitation wave targeting on‑premises SharePoint Server, rolling out out‑of‑band fixes for two freshly numbered zero‑days—CVE‑2025‑53770 and the closely related CVE‑2025‑53771—that attackers have been using since mid‑July to hijack corporate portals and plant a web‑shell dubbed ToolShell. The company released security updates late on 19 July for SharePoint Server Subscription Edition (KB 5002768) and SharePoint 2019 (KB 5002754), but confirmed that SharePoint 2016 remains unpatched while the update “finishes validation.”

ToolShell abuses an unsafe‑deserialisation flaw inside SharePoint’s ASP.NET workflow engine. An unauthenticated attacker can send one crafted SOAP request to a publicly exposed server and immediately run arbitrary code as the SharePoint service account—no credentials, no multifactor prompts. From there the intruder drops a 9 KB ASPX file (ToolShell.aspx) into /_layouts/15/, giving full command execution, credential dumping and lateral‑movement ability across the Windows domain. Eye Security telemetry shows the technique has already breached at least 75 organisations worldwide, including financial firms, a defence supplier and two European universities.

 

Patch status at a glance

Product Fixed? Security‑update KB Notes
SharePoint Subscription Edition Yes KB 5002768 Apply immediately, then rotate machine keys
SharePoint Server 2019 Yes KB 5002754 Same guidance as above
SharePoint Server 2016 No — Use Microsoft’s mitigation script and, if possible, pull the server off the public internet until the patch ships

Microsoft stresses that SharePoint Online (Microsoft 365) is not affected, and all activity seen to date targets self‑hosted deployments.

Mandatory mitigations for 2016 shops

Until the 2016 fix lands, Redmond and CISA both recommend a three‑step defensive stance:

Also worth reading
Microsoft’s Patch Tuesday Shows AI Is Finding Bugs Fast Microsoft And ILO Take Digital Skills Training To Kenya’s Refugee Youth Microsoft’s AI Buildout Runs Into The Hard Math Of Chips And Power Microsoft’s China Retreat Redraws Big Tech’s AI Map US Backs OpenAI In Copyright Fight OpenAI And Big Tech Warn The World Has Months To Prepare For AI Hacks
  1. Run Microsoft’s PowerShell hardening script to disable RPC endpoints exploited by ToolShell and enforce strict request filtering.
  2. Enable AMSI scanning (Defender or equivalent) on every SharePoint server to block malicious requests before they reach IIS.
  3. Rotate ASP.NET machine keys after any security change—and again once the final patch is applied—to invalidate stolen session cookies.

CISA has added CVE‑2025‑53770 to its Known Exploited Vulnerabilities (KEV) catalogue, giving U.S. federal agencies 48 hours to apply the available updates or disconnect vulnerable servers.

How the attack unfolds

Initial access: a single SOAP envelope triggers the deserialization bug.
Payload drop: ToolShell.aspx lands under the LAYOUTS path.
Privilege escalation & spread: the shell dumps LSASS, harvests passwords inside web.config files and spawns encoded PowerShell to fan out across the network.
Post‑exploitation: defenders have observed Cobalt Strike, Bughatch and even ransomware loaders within hours of first compromise.

Hunt teams should look for:

  • newly created ToolShell.aspx, spinstall0.aspx or similarly named files in /_layouts/15 or /_layouts/16;
  • IIS worker processes (w3wp.exe) launching PowerShell ‑enc commands;
  • outbound traffic to C2 ranges 94.103.9[.]0/24 and 193.23.181[.]0/24 or the user‑agent string toolshell‑loader/1.3.

For admins, here’s what to do urgently

  1. Patch today if you run Subscription Edition or 2019; reboot and verify the build numbers.
  2. Deploy Microsoft Defender for Endpoint (or equivalent) and import the new threat signatures (Exploit:Script/SuspSignoutReq.A, Trojan:Win32/HijackSharePointServer.A).
  3. Audit logs for past exploitation going back to 18 July; many victims were breached before patches existed.
  4. Educate IT staff: any externally facing SharePoint server without these fixes is “the digital equivalent of posting admin passwords on your website,” CISA warns.

 

Microsoft says the SharePoint 2016 patch is “days, not weeks” away. Until it ships, isolating the server or enforcing Microsoft’s script is the only safe course. With proof‑of‑concept exploits now circulating on GitHub and Telegram, time is short—and the attackers have a head start. 

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • microsoft-sharepoint-104_v-variantBig1x1_w-1280_zc-3061602c
    SharePoint Zero-day Persists Despite Microsoft Patches
  • Microsoft SharePoint CTA
    Microsoft Warns of Critical SharePoint Zero-day…
  • 5cdb1bc21ea851eb0c74bf693121f711
    Chinese Hackers Exploiting SharePoint Zero-day - Microsoft
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • Windows_Server
    Emergency Windows Server updates issued by Microsoft
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
  • win10-new-1152x648
    Microsoft’s $1.50 Windows Update Fee Kicks In July 1
  • powershell-1024x683
    Microsoft Drops PowerShell 2.0 from Windows 11 & Server
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: microsoftpatchsharepointSharePoint Zero-day Vulnerabilitytoolshell
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • AI Data Centre Pollution Fight Puts Compute Boom On Trial September 14, 2026
  • Anthropic Profit Claim Comes With Big AI Cost Questions September 14, 2026
  • Trump Rejects AI Slowdown As CEOs Warn Of Safety Risks September 14, 2026
  • OpenAI. Google And Anthropic Explore AI Standards Body September 14, 2026
  • China Pushes Back As AI Safety Fight Turns Geopolitical September 14, 2026
  • Six Things That Changed in AI Video Generation in 2026 (and What Still Doesn’t Work) September 14, 2026
  • The AI Slowdown Debate Is Now A Market Problem September 14, 2026
  • AI Stocks Fall As Safety Calls Shake Market Confidence September 14, 2026
  • Revolut Breach Shows Fake Requests Can Beat Fintech Security September 13, 2026
  • Sam Altman Says OpenAI Should Not Rush Into A 2026 IPO September 13, 2026
  • Tesla Teases October 1 Roadster Reveal After Years Of Delays September 13, 2026
  • AI Rivals Now Agree The Frontier May Need A Speed Limit September 13, 2026

Browse Archives

September 2026
M T W T F S S
 123456
78910111213
14151617181920
21222324252627
282930  
« Aug    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.