← Intelligence Center

CISA: Microsoft Releases Guidance on Exploitation of SharePoint "ToolShell" Vulnerability (CVE-2025-53770)

PublishedJul 24, 2025
Updated
VendorMicrosoft
SeverityHigh
Known ExploitedYes Known Exploited
Advisory IDINTEL-000024
CVEs
CVE-2025-53770
Products
  • Microsoft SharePoint Server (on-premise)

Executive Summary

CISA is aware of active exploitation of a remote code execution vulnerability enabling unauthorized access to on-premise SharePoint servers. Publicly reported as "ToolShell", the activity provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network. CISA later released an update to the alert adding indicators of compromise (IOCs) and new detection guidance, as well as information on post-exploit actions such as the deployment of ransomware. (This record merges the original July 20, 2025 alert with the July 24, 2025 update.)

Municipal Impact

SLTT and municipal organizations running on-premise SharePoint should review the CISA alert, apply detection guidance, and monitor for indicators of compromise including post-exploit ransomware activity.

SMB Impact

SMBs running on-premise SharePoint Server should review the CISA alert and detection guidance and treat ToolShell activity as a priority incident response scenario.

Recommended Actions

  1. Review the CISA alert for CVE-2025-53770 exploitation guidance.
  2. Review the updated CISA alert for additional IOCs and new detection guidance.
  3. Monitor on-premise SharePoint deployments for indicators of compromise and post-exploit actions such as ransomware deployment.
  4. Report incidents and anomalous activity to the MS-ISAC Security Operations Center ([email protected], 1-866-787-4722).

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter