Security Advisory_ Sharepoint - ENGMicrosoft has released Out of band security patches to fix two actively exploited SharePoint Remote code execution (RCE) zero-days. These zero days are CVE-2025-53770 and CVE-2025-53771 which are being called “ToolShell”. Attackers are using these vulnerabilities to gain full control of vulnerable SharePoint servers.

Importance
  • Unauthenticated RCE: Successful exploitation lets a remote attacker run arbitrary code in the SharePoint farms context.
  • Active Attacks in the Wild: ToolShell campaigns are underway now. Waiting to patch increases risk.
  • Incomplete Previous Fixes: July Patch Tuesday updates (July 8th) did not address these new bypasses.
Actions Required
  • SharePoint Server 2019 – Install KB5002754
  • SharePoint Subscription Edition – Install KB5002768
  • SharePoint Enterprise Server – Patch pending, prepare to deploy as soon as Microsoft releases.
  • After patching, rotate your SharePoint machine keys to invalidate any tokens an attacker may have forged:
    • PowerShell: Update-SPMachineKey
    • Central Administration: Monitoring -> Review job definitions -> machine key rotation job -> Run now, then iisreset on all web front ends.
 Optional but Recommended Checks
  • Search for the file spinstall0.aspx in C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\
  • Review IIS logs for suspicious POSTs to /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx with referrer /_layouts/SignOut.aspx
  • Use Microsoft 365 Defender to query recent creation of spinstall0.aspx
If any of these indicators appear, initiate full incident response procedures immediately.

How we’re Helping
  • Patching Support: The VMaaS team is standing by to schedule or assist with emergency deployment of the above patches.
  • Threat Hunting: We’re updating detection content today and will be performing targeted hunts for ToolShell artefacts.
Take Action Today 

Ignoring these threats could leave your business vulnerable to a serious security incident. If you want to learn more about how GoSecure can help protect your organization, contact us today for a security consultation. 

Learn More About GoSecure Titan® MXDR  

GoSecure Titan® Managed Extended Detection & Response (MXDR)​

GoSecure Titan® Managed Extended Detection & Response (MXDR)​ Foundation

GoSecure Titan® Vulnerability Management as a Service (VMaaS)

GoSecure Titan® Managed Security Information & Event Monitoring (Managed SIEM)

GoSecure Titan® Managed Perimeter Defense​ (MPD)

GoSecure Titan® Inbox Detection and Response (IDR)

GoSecure Titan® Secure Email Gateway (SEG)

GoSecure Titan® Threat Modeler

GoSecure Titan® Identity

GoSecure Titan® Platform

GoSecure Professional Security Services

Incident Response Services

Security Maturity Assessment

Privacy Services

PCI DSS Services

Penetration Testing Services​

Security Operations

MicrosoftLogo

GoSecure MXDR for Microsoft

Comprehensive visibility and response within your Microsoft security environment

USE CASES

Cyber Risks

Risk-Based Security Measures

Sensitive Data Security

Safeguard sensitive information

Private Equity Firms

Make informed decisions

Cybersecurity Compliance

Fulfill regulatory obligations

Cyber Insurance

A valuable risk management strategy

Ransomware

Combat ransomware with innovative security

Zero-Day Attacks

Halt zero-day exploits with advanced protection

Consolidate, Evolve & Thrive

Get ahead and win the race with the GoSecure Titan® Platform

24/7 MXDR FOUNDATION

GoSecure Titan® Endpoint Detection and Response (EDR)

GoSecure Titan® Next Generation Antivirus (NGAV)

GoSecure Titan® Security Information & Event Monitoring (SIEM)

GoSecure Titan® Inbox Detection and Reponse (IDR)

GoSecure Titan® Intelligence

OUR SOC

Proactive Defense, 24/7

AICPA SOC Logo - Black

ABOUT GOSECURE

GoSecure is a recognized cybersecurity leader and innovator, pioneering the integration of endpoint, network, and email threat detection into a single Managed Extended Detection and Response (MXDR) service. For over 20 years, GoSecure has been helping customers better understand their security gaps and improve their organizational risk and security maturity through MXDR and Professional Services solutions delivered by one of the most trusted and skilled teams in the industry.

EVENT CALENDAR

LATEST PRESS RELEASE

GOSECURE BLOG

SECURITY ADVISORIES

 24/7 Emergency – (888)-287-5858