216.73.216.6

SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers

· Published 22/07/2025 08:34 · Modified 22/07/2025 09:29

Export JSON

Essential information

Published
22/07/2025 08:34
Modified
22/07/2025 09:29
Tags
2025-07-22 CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 remote code execution sharepoint toolshell vulnerability webshell zero-day
Related entities
2 vulnerabilities (cve), 3 observables, 12 techniques (mitre), 1 malware, 4 others

Description

A dubbed '' targeting on-premises Microsoft Servers has been actively exploited. The flaw, identified as with an accompanying bypass , allows unauthenticated . Three distinct attack clusters have been observed, each with unique tradecraft and objectives. Targets include organizations in technology consulting, manufacturing, critical infrastructure, and professional services. The exploitation enables access to 's ToolPane functionality without authentication, leading to code execution via uploaded or in-memory web components. Different webshells and techniques were employed, including a custom password-protected ASPX and a reconnaissance utility targeting cryptographic material. Immediate patching and following Microsoft's recommendations are strongly advised.

External references