HomeUpdatesMicrosoft: Emergency updates for SharePoint zero-day vulnerabilities

Microsoft: Emergency updates for SharePoint zero-day vulnerabilities

Microsoft has issued urgent security updates for Microsoft SharePoint, targeting two new zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771. The vulnerabilities are actively exploited in “ToolShell attacks ” and have so far affected more than 54 organizations worldwide.

Microsoft SharePoint zero-day vulnerabilities

When repairs aren't enough

During the Pwn2Own Berlin hacking contest last May, security researchers combined two zero-day vulnerabilities for remote code execution (RCE) in the Microsoft SharePoint environment. The exploit chain was dubbed “ToolShell.” Although Microsoft initially patched the flaws via July’s Patch Tuesday updates , the fixes proved to be insufficient. Malicious actors discovered two new zero-day vulnerabilities, bypassing previous fixes and reactivating the ToolShell attack scripts.

See also: BIND 9 vulnerabilities expose organizations to DoS attacks

Urgent Updates — Which Versions Are Covered

Microsoft reacted quickly, releasing emergency security updates for the following versions of SharePoint:

The SharePoint Server 2016 still remains without an official fix, with Microsoft stating that it is working intensively on its development.

According to official guidance, the new updates offer significantly stronger protections compared to previous fixes for the related vulnerabilities (CVE-2025-49704 and CVE-2025-49706).

Instructions to administrators: Immediately install patches & change keys

Microsoft urges SharePoint administrators to immediately apply the new updates to fix the zero-day vulnerabilities and to reset SharePoint machine keys — a critical step to prevent further exploitation.

Changes to keys can be made in two ways:

  • Via PowerShell: Running the Update-SPMachineKey cmdlet
  • Through Central Management:
    1. Go to the Central Administration site
    2. Option: Monitoring -> Review job definition
    3. Locate Machine Key Rotation Job and select Run Now
    4. Finally, restart the IIS services via iisreset.exe

See also: VMware fixed vulnerabilities used at Pwn2Own Berlin 2025

Microsoft: Emergency updates for SharePoint zero-day vulnerabilities

Signs of a Breach — What Administrators Should Check

Microsoft advises administrators to perform a thorough audit of logs and the file system, looking for specific signs of compromise. These include:

  • Creating the file:

C:\PROGRA~1\COMMON~1\MICROS~1\WEBSER~1\16\TEMPLATE\LAYOUTS\spinstall0.aspx

  • IIS log entries that include:
  1. POST request to _layouts/15/ToolPane.aspx?
  2. DisplayMode=Edit&a=/ToolPane.aspx and a HTTP referer of _layouts/SignOut.aspx

Additionally, a special Microsoft 365 Defender query to help detect the creation of the spinstall0.aspx file. If this file is present, a full server and network level investigation for potential threat distribution.

eviceFileEvents | where FolderPath has "MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS" | where FileName =~ "spinstall0.aspx" or FileName has "spinstall0" | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, FolderPath, ReportId, ActionType, SHA256 | order by Timestamp desc

See also: Cisco patches another critical ISE vulnerability

A reminder of the constant need for vigilance

This incident once again highlights the dynamic nature of cybersecurity. The speed with which cybercriminals exploited new zero-day vulnerabilities in SharePoint, even after official patches, shows that true security doesn’t stop with installing updates. It requires constant monitoring, proactive response to breach indications, and a “defense in depth” strategy.

For organizations that rely on Microsoft SharePoint, rapid response is now a must.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS