216.73.217.98

Large-scale exploitation of new SharePoint RCE vulnerability chain identified

· Published 21/07/2025 10:15 · Modified 21/07/2025 10:28

Export JSON

Essential information

Published
21/07/2025 10:15
Modified
21/07/2025 10:28
Tags
2025-07-21 CVE-2025-53770 CVE-2025-53771 exploit on-premise rce sharepoint vulnerability
Related entities
2 vulnerabilities (cve), 4 observables, 4 techniques (mitre)

Description

A new remote code execution chain, later named and by Microsoft, was discovered being exploited in the wild. The exploitation affected Servers globally, with dozens of systems compromised during two attack waves on July 18 and 19, 2025. The first wave originated from a US-based IP address (107.191.58.76) at 18:06 UTC, deploying spinstall0.aspx. The second wave, also from a US-based IP (104.238.159.149), occurred at 07:28 UTC the following day. Two additional IP addresses were identified in connection with the attacks. Organizations are advised to patch their systems and conduct compromise assessments if they suspect being affected.

External references