• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

SharePoint Zero-day Persists Despite Microsoft Patches

Paul Balo by Paul Balo
July 22, 2025
in Security
Share on FacebookShare on Twitter

Microsoft’s emergency fixes have not stemmed the “ToolShell” tide. The critical SharePoint zero‑day (CVE‑2025‑53770, CVSS 9.8) is still being weaponised to plant a tiny ASPX back‑door on unpatched servers, and incident‑response teams continue to log fresh intrusions daily. Redmond’s out‑of‑band updates published 19 July cover SharePoint Subscription Edition (KB 5002768) and SharePoint 2019 (KB 5002754), but SharePoint 2016 remains exposed, leaving thousands of on‑prem deployments reliant on a stop‑gap PowerShell script while attackers probe every internet‑facing portal they can find. 

SecurityWeek and Rapid7 say the campaign has already breached more than 75 organisations across finance, defence and higher‑education; telemetry shows ToolShell callers beaconing from IP ranges in Russia and Vietnam, with follow‑on payloads that dump LSASS, steal machine keys and pivot laterally.  In several cases the threat actor re‑entered even after administrators installed July’s cumulative updates, because the attackers had exfiltrated cryptographic material that let them mint new authentication cookies at will. Experts therefore stress that patching must be paired with machine‑key rotation and credential resets. 

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE‑2025‑53770 to its Known Exploited Vulnerabilities (KEV) catalogue, giving federal agencies 48 hours to apply Microsoft’s mitigations or disconnect affected servers. CISA’s alert notes that ToolShell exploits a deserialisation flaw in SharePoint’s workflow engine, requires no authentication and grants SYSTEM‑level code‑execution on successful hit. 

Microsoft’s interim guidance for vulnerable SharePoint 2016 boxes boils down to four actions: (1) install all July security updates, (2) run the hardening script that blocks remote procedure calls to suspect endpoints, (3) enable AMSI‑based scanning in Defender for Endpoint, and (4) rotate machine keys and reboot IIS. Redmond says the 2016 patch is “in final validation” and should land “within days,” but has not committed to a firm date. 

Detection teams should hunt for newly created ToolShell.aspx, spinstall0.aspx or similarly named files in /_layouts/15 and review logs for the user‑agent string toolshell‑loader/1.3 or outbound traffic to 94.103.9[.]0/24 and 193.23.181[.]0/24. Rapid7 warns that the campaign is “deliberate and persistence‑oriented,” with operators revisiting servers to drop Cobalt Strike and Bughatch within hours of initial compromise.

Here’s the bottom line, if your SharePoint server still faces the open internet and does not have KB 5002768 or KB 5002754 (or their forthcoming 2016 equivalent) plus rotated machine keys, you remain a sitting duck. Administrators unable to patch immediately should remove public exposure, implement Microsoft’s mitigation script and comb logs for any sign ToolShell has landed—because attackers aren’t waiting for the final update, and neither should you.

Related Posts:

  • 4025691-0-97050800-1753099410-original
    Microsoft Patches SharePoint Bug, Leaves 2016…
  • Microsoft SharePoint CTA
    Microsoft Warns of Critical SharePoint Zero-day…
  • 5cdb1bc21ea851eb0c74bf693121f711
    Chinese Hackers Exploiting SharePoint Zero-day - Microsoft
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • Azure-logo.png
    Azure Outage Blocks Access to Microsoft 365 and…
  • powershell-1024x683
    Microsoft Drops PowerShell 2.0 from Windows 11 & Server
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
  • microsoft_exchange_1500
    Microsoft Ending Exchange 2016 & 2019 Support in 30 Days

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: cybersecuritymicrosoftsharepointSharePoint Zero-day Vulnerability
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Gamers’ AI Fears are Starting to Come True, Report Warns March 15, 2026
  • Meta Plans Sweeping Layoffs as AI Costs Surge March 14, 2026
  • Chatbots Now Emerging in ‘AI Psychosis’ and Mass-Casualty Cases, Lawyer Says March 14, 2026
  • Google Chrome To Debut Support for ARM64 Linux This Spring March 14, 2026
  • Google Meet Phases Out Legacy Duo Calling March 14, 2026
  • Instagram to Remove End-to-End Encryption for DMs in May 2026 March 14, 2026
  • China Approves First Brain Implant for Commercial Use March 13, 2026
  • Microsoft Pushes AI Adoption in Africa to Counter China’s DeepSeek March 12, 2026
  • Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday March 11, 2026
  • Meta Rolls out New Features for Scam Protection March 11, 2026
  • Zoom Unveils AI Office Suite With Avatars Arriving This Month March 11, 2026
  • Adobe Adds AI Assistant To Photoshop; Firefly Gets New Editing Tools March 11, 2026

Browse Archives

March 2026
MTWTFSS
 1
2345678
9101112131415
16171819202122
23242526272829
3031 
« Feb    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.