Microsoft has issued urgent security updates for Microsoft SharePoint, targeting two new zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771. The vulnerabilities are actively exploited in “ToolShell attacks ” and have so far affected more than 54 organizations worldwide.

When repairs aren't enough
During the Pwn2Own Berlin hacking contest last May, security researchers combined two zero-day vulnerabilities for remote code execution (RCE) in the Microsoft SharePoint environment. The exploit chain was dubbed “ToolShell.” Although Microsoft initially patched the flaws via July’s Patch Tuesday updates , the fixes proved to be insufficient. Malicious actors discovered two new zero-day vulnerabilities, bypassing previous fixes and reactivating the ToolShell attack scripts.
See also: BIND 9 vulnerabilities expose organizations to DoS attacks
Urgent Updates — Which Versions Are Covered
Microsoft reacted quickly, releasing emergency security updates for the following versions of SharePoint:
The SharePoint Server 2016 still remains without an official fix, with Microsoft stating that it is working intensively on its development.
According to official guidance, the new updates offer significantly stronger protections compared to previous fixes for the related vulnerabilities (CVE-2025-49704 and CVE-2025-49706).
Instructions to administrators: Immediately install patches & change keys
Microsoft urges SharePoint administrators to immediately apply the new updates to fix the zero-day vulnerabilities and to reset SharePoint machine keys — a critical step to prevent further exploitation.
Changes to keys can be made in two ways:
- Via PowerShell: Running the Update-SPMachineKey cmdlet
- Through Central Management:
- Go to the Central Administration site
- Option: Monitoring -> Review job definition
- Locate Machine Key Rotation Job and select Run Now
- Finally, restart the IIS services via iisreset.exe
See also: VMware fixed vulnerabilities used at Pwn2Own Berlin 2025

Signs of a Breach — What Administrators Should Check
Microsoft advises administrators to perform a thorough audit of logs and the file system, looking for specific signs of compromise. These include:
- Creating the file:
C:\PROGRA~1\COMMON~1\MICROS~1\WEBSER~1\16\TEMPLATE\LAYOUTS\spinstall0.aspx
- IIS log entries that include:
- POST request to _layouts/15/ToolPane.aspx?
- DisplayMode=Edit&a=/ToolPane.aspx and a HTTP referer of _layouts/SignOut.aspx
Additionally, a special Microsoft 365 Defender query to help detect the creation of the spinstall0.aspx file. If this file is present, a full server and network level investigation for potential threat distribution.
eviceFileEvents | where FolderPath has "MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS" | where FileName =~ "spinstall0.aspx" or FileName has "spinstall0" | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, FolderPath, ReportId, ActionType, SHA256 | order by Timestamp descSee also: Cisco patches another critical ISE vulnerability
A reminder of the constant need for vigilance
This incident once again highlights the dynamic nature of cybersecurity. The speed with which cybercriminals exploited new zero-day vulnerabilities in SharePoint, even after official patches, shows that true security doesn’t stop with installing updates. It requires constant monitoring, proactive response to breach indications, and a “defense in depth” strategy.
For organizations that rely on Microsoft SharePoint, rapid response is now a must.
Source: www.bleepingcomputer.com
