Defending Against ToolShell: SharePoint's Latest Critical Vulnerability
Essential information
- Published
- 23/07/2025 23:31
- Modified
- 24/07/2025 09:34
- Tags
- 2025-07-23 CVE-2025-53770 cybersecurity patch remote code execution sharepoint threat detection toolshell vulnerability zero-day
- Related entities
- 2 observables, 15 techniques (mitre), 1 malware
Description
A critical zero-day vulnerability named ToolShell (CVE-2025-53770) has been discovered in on-premises SharePoint Server deployments. This vulnerability allows unauthenticated remote code execution, posing a significant threat to organizations worldwide. SentinelOne has detected active exploitation and provides defensive measures. ToolShell's severity is characterized by its zero-day status, high CVSS score of 9.8, no authentication requirement, and remote code execution capability. SentinelOne's defense strategy includes early identification, out-of-the-box detection logic, IOC integration, hunting queries, and proactive detection through Singularity Vulnerability Management. Recommended mitigation steps include isolating SharePoint instances, enabling AMSI, applying patches, integrating IOCs, monitoring for suspicious behavior, and conducting retroactive threat hunting.