Microsoft SharePoint Servers in Thousands of Firms Targeted Using ToolShell Zero-Day Vulnerability

Unknown threat actors are using a weaponised version of an exploit showcased at Pwn2Own Berlin in May to target SharePoint servers around the world.

Advertisement
Written by David Delima | Updated: 21 July 2025 16:55 IST
Highlights
  • SharePoint servers are being actively targeted using an RCE exploit
  • Attackers can gain persistent access to a system even after a reboot
  • Microsoft has patched two versions of its SharePoint server software

Microsoft has urged customers to install the latest security patches on SharePoint servers

Photo Credit: Unsplash/ Ed Hardie

Microsoft's SharePoint software for servers is being targeted by malicious actors using a remote code execution (RCE) vulnerability to gain unauthorised access, according to the company. The security flaw allows threat actors to target on-premise servers at thousands of firms with SharePoint servers. Researchers state that once attackers have breached these servers, they can gain persistent access, even if the server is patched. Microsoft says it has rolled out a security patch that can mitigate active attacks, and more are on the way.

Threat Actors Gain Persistent Access to Microsoft SharePoint Servers 

The vulnerability affecting SharePoint on-premise servers was reported on July 18 by researchers at European cybersecurity firm Eye Security. They explained that threat actors are using a zero-day, or previously unknown vulnerability, (which has since been identified as CVE-2025-53770 and CVE-2025-53770) to gain access to servers, without using brute force attacks or phishing.

The new zero-day vulnerability is a weaponised version of an exploit that was showcased at Pwn2Own Berlin (a security contest) earlier this year. The US CISA warns that threat actors can execute code on the network, and gain access to all SharePoint content on a server, such as internal configurations or file systems.

Advertisement

According to the researchers, these attackers could use stolen keys to act on behalf of legitimate users. As a result, these attackers can modify components and install other code that lets them retain access to the servers after security patches are installed, or the systems are rebooted.

Advertisement

Palo Alto Networks' Unit 42 wrote on X (formerly Twitter) that the threat intelligence team was observing "active global exploitation" of SharePoint vulnerabilities that were being used to target organisations around the world. Additional details of these attacks were shared via Unit 42's GitHub threat intel repository.

A day later, the Microsoft Security Response Center (MSRC) issued an advisory that confirms the security flaw is being actively exploited by threat actors. The company says it has released a security patch to protect SharePoint Subscription Edition and SharePoint 2019 servers against active attacks using this exploit. 

Advertisement

At the time of publishing this story, Microsoft has yet to roll out a security update for SharePoint 2016 servers. The company's advisory also urges customers to apply the July 2025 security updates, set up the Antimalware Scan Interface (AMSI) in SharePoint, and deploy Microsoft Defender or similar solutions.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Nothing Phone 3a Lite Goes on Sale in India at This Price
  6. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  7. Here's What India Searched For the Most on Google in 2025
  8. Realme 16 Pro+ 5G New Leak Reveals Storage and Colour Variants
  9. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  10. Realme Says It Will Launch Two New Narzo Smartphones in India Soon
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  4. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  5. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  6. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  7. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  8. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  9. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  10. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.