CISA: Microsoft Releases Guidance on Exploitation of SharePoint "ToolShell" Vulnerability (CVE-2025-53770)
- •Microsoft SharePoint Server (on-premise)
Executive Summary
CISA is aware of active exploitation of a remote code execution vulnerability enabling unauthorized access to on-premise SharePoint servers. Publicly reported as "ToolShell", the activity provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network. CISA later released an update to the alert adding indicators of compromise (IOCs) and new detection guidance, as well as information on post-exploit actions such as the deployment of ransomware. (This record merges the original July 20, 2025 alert with the July 24, 2025 update.)
Municipal Impact
SLTT and municipal organizations running on-premise SharePoint should review the CISA alert, apply detection guidance, and monitor for indicators of compromise including post-exploit ransomware activity.
SMB Impact
SMBs running on-premise SharePoint Server should review the CISA alert and detection guidance and treat ToolShell activity as a priority incident response scenario.
Recommended Actions
- Review the CISA alert for CVE-2025-53770 exploitation guidance.
- Review the updated CISA alert for additional IOCs and new detection guidance.
- Monitor on-premise SharePoint deployments for indicators of compromise and post-exploit actions such as ransomware deployment.
- Report incidents and anomalous activity to the MS-ISAC Security Operations Center ([email protected], 1-866-787-4722).
Grey Matter Analysis
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter