ToolShell: a story of five vulnerabilities in Microsoft SharePoint
ID: 1b900b15-6892-5db4-85c5-e354c7fa2aa9
STIX ID: report--1b900b15-6892-5db4-85c5-e354c7fa2aa9
Feed Name: Securelist by Kaspersky
Date Published: 2025-07-25
Date Updated: 2026-04-29
Author: Boris Larin, Georgy Kucherin, Ilya Savelyev
Kaspersky researchers analyzed a widely exploited SharePoint remote code execution chain dubbed "ToolShell" (CVE-2025-49704 + CVE-2025-49706 and subsequent fixes CVE-2025-53770/53771). Attackers used an unauthenticated POST request to bypass authentication and trigger unsafe XML deserialization (ExpandedWrapper technique) to execute payloads; the exploit was observed in the wild from July 18, 2025 across multiple countries and sectors. Microsoft issued out-of-band patches, but incomplete mitigations and easy bypasses left many servers vulnerable until proper updates and configuration upgrades were applied; Kaspersky provides detection verdicts and urges rapid patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
