SharePoint zero-day vulnerabilities CVE-2025-53770 and 53771 exploited by ToolShell
ID: fb12f8b5-80bc-50f5-879c-4b71803d05d3
STIX ID: report--fb12f8b5-80bc-50f5-879c-4b71803d05d3
Feed Name: ThreatLocker Blog
ToolShell is a set of critical, actively exploited vulnerabilities in supported on-premises SharePoint Server (Subscription Edition, 2019, 2016) where CVE-2025-53771 (path traversal) allows unauthenticated access to ToolPane.aspx and CVE-2025-53770 (deserialization) enables remote code execution when chained. Successful exploitation can be used to deploy malware, move laterally, exfiltrate data, or deliver ransomware; the report lists affected SharePoint versions and recommends immediate patching, enabling AMSI in Full Mode, rotating ASP.NET machine keys, and applying ThreatLocker-specific controls and policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
