logo

0day Vulnerability in Microsoft Sharepoint Exploited in-the-Wild (Campaign)

ID: c27c5092-26cc-5e8b-aa61-716ce64e0a79

STIX ID: report--c27c5092-26cc-5e8b-aa61-716ce64e0a79

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-07-20

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Microsoft disclosed two zero-day vulnerabilities in on-premises SharePoint (CVE-2025-53770: unsafe deserialization RCE and CVE-2025-53771: authentication bypass via Referer spoofing) that were actively exploited in the wild as part of a chained exploit called ToolShell. Attackers bypass authentication with a spoofed POST to the ToolPane endpoint, submit serialized payloads that trigger unsafe deserialization to drop an ASPX webshell (spinstall0.aspx), extract machineKeys, and then sign ViewState payloads to achieve arbitrary code execution; emergency patches were issued after exploitation was observed in mid-July 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.