logo

CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

ID: a443af85-0cef-5abb-8539-ccd93cbd5e34

STIX ID: report--a443af85-0cef-5abb-8539-ccd93cbd5e34

Feed Name: Crowdstrike Blog

Threat Score
90/100

Date Published: 2025-07-21

Date Updated: 2026-04-27

Author: CrowdStrike Engineering

...
...

CrowdStrike reports critical SharePoint vulnerabilities (CVE-2025-53770 and CVE-2025-53771) that are actively exploited in the wild; the advisory supplies mitigation guidance, Falcon Exposure Management checks to find vulnerable systems, and Next‑Gen SIEM detection rules and correlation queries to identify exploitation activity (IIS log ingestion, patterns of POST requests to ToolPane.aspx, PowerShell execution tied to w3wp.exe, and ASPX file writes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.