CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation
ID: a443af85-0cef-5abb-8539-ccd93cbd5e34
STIX ID: report--a443af85-0cef-5abb-8539-ccd93cbd5e34
Feed Name: Crowdstrike Blog
Threat Score
CrowdStrike reports critical SharePoint vulnerabilities (CVE-2025-53770 and CVE-2025-53771) that are actively exploited in the wild; the advisory supplies mitigation guidance, Falcon Exposure Management checks to find vulnerable systems, and Next‑Gen SIEM detection rules and correlation queries to identify exploitation activity (IIS log ingestion, patterns of POST requests to ToolPane.aspx, PowerShell execution tied to w3wp.exe, and ASPX file writes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
