Massive Microsoft 0-Day Exploited and Unfixed - Threat Wire

Quick Overview

Microsoft's SharePoint zero-day vulnerability (CVE-2025-53770), discovered on July 18, 2025, allowed attackers to bypass authentication by exploiting a flaw in how SharePoint handles deserialization via its ASP.NET page framework, impacting over 75% of SharePoint servers. While Microsoft released a patch on July 19, 2025, a new chain, ToolShell (CVE-2025-49706 + CVE-2025-49704), emerged that bypasses this patch by extracting validation keys directly from memory or configuration, enabling fully valid, signed ViewState payloads for remote code execution.

Key Points: Microsoft's SharePoint zero-day vulnerability (CVE-2025-53770) was exploited in the wild, affecting over 75% of SharePoint servers. A new exploit chain, ToolShell (CVE-2025-49706 + CVE-2025-49704), bypasses Microsoft's patch by extracting validation keys. The ToolShell exploit enables remote code execution with full persistence and zero authentication. The US Department of Defense received $1 billion for offensive cyber operations under the 'One Big Beautiful Bill Act'. This allocation contrasts with broader cybersecurity budget cuts and raises concerns about potential cyber retaliation. Dell confirmed a breach of its test lab platform by the 'World Leaks' extortion group, which has since been active against 49 organizations.

Context: This report covers two significant cybersecurity events: a critical zero-day vulnerability in Microsoft SharePoint that was actively exploited and a US government initiative to fund offensive cyber operations. The SharePoint vulnerability, CVE-2025-53770, was discovered and exploited before a patch was available, and a subsequent exploit chain, ToolShell, was developed to bypass the initial fix. Separately, the US is allocating substantial funds for offensive cyber capabilities, which has drawn attention due to ongoing cybersecurity threats and budget considerations.

Detailed Analysis

On July 18, 2025, Microsoft announced the discovery and exploitation of a critical zero-day vulnerability in SharePoint servers, identified as CVE-2025-53770. This vulnerability, which received a CVSS score of 9.8, allowed attackers to bypass authentication by exploiting a flaw in the deserialization process handled by the ASP.NET page framework. The exploit chain, dubbed 'ToolShell' (CVE-2025-49706 + CVE-2025-49704), was first identified by Eye Security and was found to be actively exploited in the wild, impacting over 75% of SharePoint servers globally, including government and major corporations. Microsoft released a security update on July 19, 2025, to address the initial vulnerability. However, the ToolShell chain was quickly updated to bypass this patch by extracting the 'ValidationKey' directly from memory or configuration. This leaked cryptographic material allows attackers to craft fully valid, signed ViewState payloads, which are accepted by the server as trusted input, enabling remote code execution without requiring credentials. This technique mirrors a design weakness exploited in 2021 but is now packaged as a modern zero-day chain with automatic shell drop, full persistence, and zero authentication. The vulnerability was initially reported to affect on-premise SharePoint servers, with Microsoft 365 SharePoint instances not being impacted. The US Department of Defense has also received a $1 billion allocation for 'offensive cyber operations' under the 'One Big Beautiful Bill Act,' which contrasts with broader efforts to slash cybersecurity spending and has raised concerns among senators about potential cyber retaliation.

Raw markdown version of this recap