URGENT ADVISORY: ToolShell — Critical SharePoint RCE Chain Under Active Exploitation

URGENT: CVE-2025-53770/53771 ToolShell exploit chain under active exploitation since July 17, 2025. If you run on-prem SharePoint Server, you are vulnerable to unauthenticated RCE.

URGENT ADVISORY: ToolShell — Critical SharePoint RCE Chain Under Active Exploitation

TL;DR: If you run on-premises SharePoint Server — 2013, 2016, 2019, or Subscription Edition — you are vulnerable to unauthenticated remote code execution. Attackers have been exploiting the bypass chain since July 17, 2025 (before Microsoft issued emergency out-of-band patches on July 20). The exploit chain bypasses authentication, executes arbitrary code, steals cryptographic keys, and plants persistence that survives re-patching. SharePoint Online / Microsoft 365 is not affected.

Topics: