In July 2025, Microsoft disclosed a critical zero-day vulnerability in its on-premises SharePoint Server, identified as CVE-2025-53770. This flaw, with a CVSS score of 9.8, allows unauthenticated remote code execution, enabling attackers to gain full control over affected servers. The vulnerability affects SharePoint Server 2016, 2019, and the Subscription Edition, while SharePoint Online remains unaffected.
The exploitation of CVE-2025-53770, dubbed "ToolShell," involves attackers sending...