Back
Outfaze Security Team

Outfaze Security Team

SharePoint ToolShell: Patch, Rotate Keys, and Investigate

SharePoint ToolShell: Patch, Rotate Keys, and Investigate

On July 19, 2025, Microsoft warned of active attacks against on-premises SharePoint Server. The vulnerabilities later tracked as CVE-2025-53770 and CVE-2025-53771 required more than a routine maintenance response.

Microsoft's guidance paired immediate security updates with AMSI and endpoint protection, machine-key rotation, and threat hunting. SharePoint Online in Microsoft 365 was not affected, making precise product inventory essential.

Why ToolShell required both remediation and investigation

Observed attackers could reach exposed on-premises servers, execute code, deploy web shells, and retrieve ASP.NET machine-key material. A patched server could therefore remain at risk if stolen keys or attacker persistence were not addressed.

The distinction between supported SharePoint Server and SharePoint Online also mattered. Teams needed exact edition, version, exposure, update, and logging evidence rather than a broad statement that the organization 'uses SharePoint.'

Build an evidence-led response

Identify every on-premises SharePoint server, preserve web, Windows, endpoint, and network evidence, then apply Microsoft's current cumulative updates. Follow the vendor sequence for restarting IIS and rotating machine keys across the farm.

Hunt for published indicators and unexpected files, processes, scheduled tasks, account changes, and outbound connections. If compromise is suspected, scope connected identities and systems before returning the service to normal operation.

  • Separate on-premises SharePoint from SharePoint Online inventory.
  • Record patch level and key-rotation completion for every farm member.
  • Treat web-shell evidence as an incident, not a patch exception.
  • Retain logs outside the SharePoint servers.

Put the lesson into practice

  1. Confirm product, version, exposure, and owner.
  2. Preserve evidence and apply the latest supported updates.
  3. Rotate machine keys using Microsoft's current procedure.
  4. Hunt across server, identity, endpoint, and network data.
  5. Validate remediation and monitor for renewed access.

Related Outfaze guidance

Authoritative sources