Join our Newsletter — 33% off our NHI Course

SharePoint zero-day exploitation: what IAM teams need to do now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: CVE-2025-53770 is actively exploited against on-premises SharePoint through unauthenticated code execution and machine-key theft, allowing attackers to persist even after patching, according to Abnormal AI. Patching alone does not remove forged-token footholds, so identity teams have to treat cryptographic material, session state, and exposure paths as part of the incident surface.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “SharePoint “ToolShell” Exploit: Guidance for CISOs”.

Key questions

Q: What breaks when SharePoint machine keys are exposed in a server compromise?

A: When machine keys are exposed, patching the vulnerable code no longer guarantees recovery because the attacker may still be able to forge trusted authentication tokens.

Q: Why does compromised SharePoint infrastructure create an identity persistence problem?

A: Because the attacker is no longer relying only on the original exploit.

Q: How do security teams know whether SharePoint compromise is still active after patching?

A: They should look for signs that the attacker still controls identity material, such as forged tokens, strange server-side files, suspicious logins, or repeated access from unexpected sources.

Practitioner guidance

  • Rotate SharePoint machine keys and auth certificates Treat machine-key rotation as mandatory containment when on-prem SharePoint compromise is suspected, because forged tokens can survive the patch cycle.
  • Invalidate session tokens and authentication artefacts Force revocation of any tokens that could have been signed by compromised keys, and confirm that old sessions cannot be replayed against the environment.
  • Hunt for web shells and forged-token activity Review SharePoint logs, EDR telemetry, and unusual .aspx files for signs that the attacker established persistence before or after patching.

Bottom line: This breach shows that SharePoint compromise becomes an identity problem when machine keys and token-signing material are stolen.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Identity trust has become the persistence layer: This breach worked because SharePoint machine keys were not just credentials, they were trust anchors. Once attackers could forge authentication tokens, patching the vulnerable endpoint no longer removed the attacker’s presence. The practitioner lesson is that incident scope must expand from vulnerable software to the signing material that makes sessions believable.

A question worth separating out:

Q: What should teams do when SharePoint and cloud collaboration services are mixed in one environment?

A: Separate the exposure models clearly. Microsoft 365 and SharePoint Online are not affected by this flaw, but on-premises SharePoint can still be vulnerable and can become a local identity compromise source. Teams should document which systems are cloud-hosted, which are self-managed, and which trust artefacts each one owns.

👉 Read our full editorial: SharePoint zero-day exploitation exposes machine key persistence risk


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.