← Back to Feed
MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities
CVE-2025-49704CVE-2025-49706CVE-2025-53770CVE-2025-53771
August 6, 2025 · CISA Advisories · Severity: HIGH
CISA received six files related to Microsoft SharePoint vulnerabilities, including an exploit chain known as ToolShell that uses CVE-2025-49706 and CVE-2025-49704. The analysis includes Base64 encoded .NET DLL binaries that retrieve machine key settings from ASP.NET applications. CISA assesses that additional vulnerabilities may be chained to bypass previously disclosed ones.
Key Takeaways
- Threat actors chained CVE-2025-49706 and CVE-2025-49704 in the ToolShell exploit chain.
- Analyzed DLLs retrieve machine key settings and add them to HTTP response headers.
- CISA assesses exploitation of CVE-2025-53771 is likely due to its chainability.