# Massive Microsoft 0-Day Exploited and Unfixed - Threat Wire

Source: https://www.youtube.com/watch?v=N87F6ifqxo0
Recap page: https://rapidrecap.app/video/N87F6ifqxo0
Generated: 2025-07-23T18:02:28.632+00:00

---
## Quick Overview

Microsoft's SharePoint zero-day vulnerability (CVE-2025-53770), discovered on July 18, 2025, allowed attackers to bypass authentication by exploiting a flaw in how SharePoint handles deserialization via its ASP.NET page framework, impacting over 75% of SharePoint servers. While Microsoft released a patch on July 19, 2025, a new chain, ToolShell (CVE-2025-49706 + CVE-2025-49704), emerged that bypasses this patch by extracting validation keys directly from memory or configuration, enabling fully valid, signed ViewState payloads for remote code execution.

**Key Points:**
- Microsoft's SharePoint zero-day vulnerability (CVE-2025-53770) was exploited in the wild, affecting over 75% of SharePoint servers.
- A new exploit chain, ToolShell (CVE-2025-49706 + CVE-2025-49704), bypasses Microsoft's patch by extracting validation keys.
- The ToolShell exploit enables remote code execution with full persistence and zero authentication.
- The US Department of Defense received $1 billion for offensive cyber operations under the 'One Big Beautiful Bill Act'.
- This allocation contrasts with broader cybersecurity budget cuts and raises concerns about potential cyber retaliation.
- Dell confirmed a breach of its test lab platform by the 'World Leaks' extortion group, which has since been active against 49 organizations.

![Screenshot at 00:13: A text overlay clearly states 'SharePoint 0-Day Went Unpatched', summarizing the core issue discussed in the first part of the video.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-13.png)

**Context:** This report covers two significant cybersecurity events: a critical zero-day vulnerability in Microsoft SharePoint that was actively exploited and a US government initiative to fund offensive cyber operations. The SharePoint vulnerability, CVE-2025-53770, was discovered and exploited before a patch was available, and a subsequent exploit chain, ToolShell, was developed to bypass the initial fix. Separately, the US is allocating substantial funds for offensive cyber capabilities, which has drawn attention due to ongoing cybersecurity threats and budget considerations.

## Detailed Analysis

On July 18, 2025, Microsoft announced the discovery and exploitation of a critical zero-day vulnerability in SharePoint servers, identified as CVE-2025-53770. This vulnerability, which received a CVSS score of 9.8, allowed attackers to bypass authentication by exploiting a flaw in the deserialization process handled by the ASP.NET page framework. The exploit chain, dubbed 'ToolShell' (CVE-2025-49706 + CVE-2025-49704), was first identified by Eye Security and was found to be actively exploited in the wild, impacting over 75% of SharePoint servers globally, including government and major corporations. Microsoft released a security update on July 19, 2025, to address the initial vulnerability. However, the ToolShell chain was quickly updated to bypass this patch by extracting the 'ValidationKey' directly from memory or configuration. This leaked cryptographic material allows attackers to craft fully valid, signed ViewState payloads, which are accepted by the server as trusted input, enabling remote code execution without requiring credentials. This technique mirrors a design weakness exploited in 2021 but is now packaged as a modern zero-day chain with automatic shell drop, full persistence, and zero authentication. The vulnerability was initially reported to affect on-premise SharePoint servers, with Microsoft 365 SharePoint instances not being impacted. The US Department of Defense has also received a $1 billion allocation for 'offensive cyber operations' under the 'One Big Beautiful Bill Act,' which contrasts with broader efforts to slash cybersecurity spending and has raised concerns among senators about potential cyber retaliation.

### SharePoint Vulnerability Discovery

- CVE-2025-53770 discovered July 18, 2025, with a CVSS score of 9.8
- Exploited in the wild, impacting over 75% of SharePoint servers
- Microsoft released a patch on July 19, 2025

### ToolShell Exploit Chain

- Identified by Eye Security, uses CVE-2025-49706 + CVE-2025-49704
- Bypasses initial patch by extracting ValidationKey from memory/configuration
- Enables creation of valid, signed ViewState payloads for RCE

### Exploit Mechanism

- Leverages deserialization flaw in ASP.NET page framework
- Mirrors 2021 design weakness but updated for modern zero-day chain
- Achieves shell drop, persistence, and zero authentication

### Impacted Systems

- Primarily affects on-premise SharePoint servers
- Microsoft 365 SharePoint instances not impacted

### Government Cyber Spending

- US earmarks $1B for 'offensive cyber operations'
- Contrasts with cybersecurity budget cuts
- Concerns raised about potential cyber retaliation

![Screenshot at 00:01: Host introduces the topic of a critical SharePoint zero-day vulnerability.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-01.png)
![Screenshot at 00:07: Aerial view of city blocks, symbolizing the widespread impact of cyber threats.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-07.png)
![Screenshot at 00:08: A graphic interface displaying system information and threat data.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-08.png)
![Screenshot at 00:09: The 'Threat Wire' title card appears, setting the tone for cybersecurity news.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-09.png)
![Screenshot at 00:13: Text overlay: 'SharePoint 0-Day Went Unpatched', highlighting the vulnerability.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-13.png)
![Screenshot at 00:33: A detailed report card for the SharePoint 0-day vulnerability \(CVE-2025-53770\).](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-00-33.png)
![Screenshot at 01:17: A quote explaining the technical details of the ToolShell exploit chain.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-01-17.png)
![Screenshot at 02:25: Text overlay: 'The US Goes On The Cyber Offensive', introducing a new segment.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-02-25.png)
![Screenshot at 02:29: A news article about the US earmarking $1 billion for offensive cyber operations.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-02-29.png)
![Screenshot at 03:30: Dell confirms a breach of its test lab platform by the 'World Leaks' extortion group.](https://ss.rapidrecap.app/screens/N87F6ifqxo0/00-03-30.png)
