
THREAT LEVEL - HIGH
21-07-2025
New Critical Microsoft SharePoint Vulnerability
Threat Level Description
IthacaLabs has maintained the Threat Level (High) adding a new observation:
An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.
Description
We have observed that a critical zero‑day vulnerability affecting Microsoft SharePoint Server has been identified.
A remote unauthenticated attacker, by exploiting this issue, could execute arbitrary code and gain full control over the SharePoint server, allowing them to read, modify, or delete site content and pivot further into the network.
This vulnerability, tracked as CVE‑2025‑53770, also known as ”ToolShell”, is rooted in the SharePoint ASP.NET deserialization process. The issue arises from improper deserialization of untrusted data [CWE‑502] in the SharePoint front‑end components that could allow a remote unauthenticated attacker to execute arbitrary commands via specially crafted HTTP requests.
Note that this vulnerability has been exploited in the wild for some time.
Identified actions of an attack, exploiting this vulnerability, have shown that the exploitation has been automated through scripts that deploy a web shell, issue POST requests to “/_layouts/15/ToolPane.aspx?DisplayMode=Edit”, and exfiltrate SharePoint content and configuration files.
Affected Products:
- Microsoft SharePoint Server 2019 – vulnerable until Security Update KB 5002741 is applied (fixed build 16.0.10417.20027)
- Microsoft SharePoint Enterprise Server 2016 – vulnerable until Security Update KB 5002744 is applied (fixed build 16.0.5508.1000)
The vulnerabilities apply only to on‑premises SharePoint Server installations. SharePoint Online (Microsoft 365) is not impacted as per Microsoft.
Recommendation(s)
You should proceed immediately and apply the relevant security patches provided by Microsoft.
If it is not possible to install the latest security update immediately, then implement the following compensating controls:
- Enable and correctly configure Antimalware Scan Interface (AMSI) integration on every SharePoint server and run an Antivirus to block exploitation attempts.
- Rotate ASP.NET machine keys on all SharePoint servers after patching or enabling AMSI, then restart IIS.
- Deploy an EDR to detect post‑exploitation activity such as web‑shell deployment.
- Harden network exposure for unpatched servers by restricting external access, placing them behind a VPN, or disconnecting them from the Internet entirely until updates are applied.
- Monitor for indicators of compromise (IOCs), including creation of the web‑shell ”spinstall0.aspx”, unusual POST requests to “/_layouts/15/ToolPane.aspx?DisplayMode=Edit”, and suspicious PowerShell spawned by “w3wp.exe”.
Applying the security updates and following the mitigation steps above are critical to protect your on‑premises SharePoint environment from active exploitation.
You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.
References:
- Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability (CVE-2025-53770) | CISA
- CVE Record: CVE-2025-53770
- Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center



