216.73.216.6

Toolshell: Large-scale exploitation of new SharePoint RCE vulnerability chain identified

· Published 21/07/2025 10:15 · Modified 21/07/2025 11:57

Export JSON

Essential information

Published
21/07/2025 10:15
Modified
21/07/2025 11:57
Tags
2025-07-21 CVE-2025-53770 CVE-2025-53771 exploit on-premise rce sharepoint toolshell vulnerability webshell
Related entities
4 techniques (mitre)

Description

This pulse highlights an ongoing mass exploitation campaign targeting on-premises Microsoft servers using a newly disclosed remote code execution () chain dubbed . Discovered on July 18, 2025, by Eye Security, the attack chain is now tracked as and , combining two previously known but unpatched vulnerabilities. The attackers ToolPane.aspx via unauthenticated HTTP requests, dropping a custom ASPX (spinstall0.aspx) into the site.

External references