Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ToolShell is the name used for a sequence of vulnerabilities and exploitation activity targeting on-premises Microsoft SharePoint Server—not one vulnerability that affects every SharePoint deployment. Microsoft said SharePoint Online in Microsoft 365 was not affected. The attacks and emergency guidance described here date to July 2025; administrators should check Microsoft’s current support and security-update instructions before acting.

What does “ToolShell” refer to?

ToolShell describes related SharePoint vulnerabilities and the exploitation of them. CERT-EU says the initial label covered CVE-2025-49704 and CVE-2025-49706, for which updates were disclosed on July 8, 2025. Later, active exploitation of a variation was detected, and investigators identified CVE-2025-53770 and CVE-2025-53771 as vulnerabilities that bypassed the earlier updates. The sequence is important: installing an earlier update did not address the later bypass vulnerabilities. See CERT-EU’s July 22 joint statement and technical advisory.

The accounts describe different milestones. Microsoft said it observed attempted exploitation of CVE-2025-49704 and CVE-2025-49706 as early as July 7, 2025. CERT-EU dates disclosure and updates for those vulnerabilities to July 8, and says active exploitation of a variation was detected July 18. Microsoft’s threat analysis, published July 22 and updated July 23, describes actors targeting internet-facing SharePoint servers. These dates are observations and disclosure events, not a single start date for all activity.

How severe were the later vulnerabilities?

CERT-EU described CVE-2025-53770 as unauthenticated network code execution resulting from deserialization of untrusted data, with a CVSS score of 9.8. It described CVE-2025-53771 as a path-traversal spoofing issue, with a CVSS score of 6.3. These are CERT-EU’s 2025 scores; they describe different vulnerabilities and should not be treated as interchangeable ratings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is my SharePoint environment affected?

The key distinction is where SharePoint runs. Microsoft’s July 2025 customer guidance says: “These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.” Read the Microsoft guidance for its dated product and update instructions.

Microsoft’s July 2025 instructions covered SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. For 2019 and 2016, Microsoft listed both base and language-pack updates, so check that the update for each installed language is included. CERT-EU warned that older, unsupported SharePoint versions should be considered vulnerable and would not be patched by Microsoft. Because support status and update instructions can change, verify the current lifecycle and guidance with Microsoft rather than relying on a 2025 product list alone.

  • Inventory each on-premises SharePoint version, installed updates, language packs, and whether the server is reachable from the internet.
  • Compare that inventory with Microsoft’s current update guidance for the specific version and language configuration.
  • If you use SharePoint Online only, Microsoft’s cited guidance says these vulnerabilities did not affect that service; this does not establish anything about unrelated security issues.

What did attackers do?

Microsoft Threat Intelligence reported exploitation against internet-facing SharePoint servers and observed web-shell deployment, including files named spinstall0.aspx and similarly named variants. Microsoft said attackers attempted to obtain SharePoint machine-key material. Its analysis describes how the web shell could support persistence, credential access, lateral movement, and further activity; those are reported capabilities and observations, not proof that every targeted server experienced every step.

Microsoft attributed observed exploitation to Linen Typhoon, Violet Typhoon, and Storm-2603. It assessed Storm-2603 as likely China-based with moderate confidence and reported observing that actor deploy ransomware. This is Microsoft’s assessment, not an independently settled attribution or a claim that all affected organizations were hit by ransomware. Its account is not a reliable campaign-wide victim count; the sources cited here do not establish how many organizations were compromised. See Microsoft’s threat analysis for its observations, indicators, and hunting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should administrators respond?

Use the response path that fits what is known about the server. If compromise is plausible, preserve evidence and follow incident-response direction before routine patching. CERT-EU’s July 22, 2025 joint statement advises isolating affected instances and assessing for compromise before updating, because patching a compromised system may destroy forensic evidence. Its sequence is not the same as the ordinary path for a server with no indication of compromise.

If compromise is suspected

  1. Isolate the affected SharePoint instance from networks to limit further access or activity.
  2. Engage your organization’s incident-response process and follow relevant national cybersecurity authority or CERT guidance. Assess the system for compromise and preserve forensic evidence before updating if doing so could destroy evidence.
  3. Once exploitation has been assessed and the appropriate response determined, apply the current Microsoft security updates for the supported server version.

CERT-EU’s wording is explicit: “We advise isolating affected instances immediately at the network level, following your national cybersecurity authority’s or CERT-EU’s instructions to assess for compromise, and updating systems once exploitation has been ruled out, as patching a compromised system may destroy forensic evidence.” The joint statement provides the dated advice.

If there is no evidence of compromise

  1. Install the latest applicable Microsoft security update for the supported SharePoint version, following Microsoft’s current instructions and including the required language-pack update where applicable.
  2. Ensure AMSI is enabled and correctly configured, and that antivirus is running on the SharePoint servers. Microsoft describes AMSI Full Mode for environments where HTTP request-body scanning is available.
  3. After applying updates or enabling AMSI, rotate the SharePoint ASP.NET machine keys and restart IIS on all SharePoint servers, following Microsoft’s documented procedure.

Microsoft’s customer guidance documents the PowerShell cmdlets Set-SPMachineKey and Update-SPMachineKey, followed by iisreset.exe. Consult the current Microsoft instructions for prerequisites and exact operational details rather than treating command names alone as a complete procedure.

If you cannot promptly patch or enable AMSI

Microsoft’s July 2025 threat guidance advises disconnecting a server from the internet if AMSI cannot be enabled and the security update is not installed. If disconnecting is not possible, it suggests restricting unauthenticated traffic through an authenticated VPN, proxy, or gateway. These are risk-reduction measures, not substitutes for the applicable update and a complete compromise assessment. See Microsoft’s threat guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should defenders hunt for?

Microsoft identifies spinstall0.aspx and similarly named web-shell files as indicators to investigate. Use Microsoft’s threat analysis and customer guidance for the associated detection names and hunting queries; do not assume a matching alert alone proves ToolShell compromise. Microsoft notes that alerts can also result from unrelated activity, so validate findings in context, including the affected server, timing, and surrounding evidence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.