ToolShell: Details of CVEs affecting SharePoint servers
ID: bf2f4203-36f9-57af-aca6-12e4767536aa
STIX ID: report--bf2f4203-36f9-57af-aca6-12e4767536aa
Feed Name: Cisco Talos
Cisco Talos describes active exploitation in the wild of unauthenticated SharePoint Server path traversal/RCE vulnerabilities (CVE-2025-53770 and CVE-2025-53771) affecting on‑premises SharePoint Server (2016, 2019, Subscription Edition). Microsoft and CISA have released patches and guidance; Talos and other vendors published detections (Snort SIDs 65092/65183, ClamAV SharpyShell signature, Splunk analytics) and recommend applying updates, rotating ASP.NET machine keys, and enabling AMSI to mitigate post-compromise activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
