Microsoft addressed CVE-2025-49704, a remote-code-execution vulnerability in SharePoint Server, but subsequent research showed that the initial remediation could be bypassed. The flaw became part of the SharePoint attack path commonly tracked as ToolShell, in which attackers could execute code on vulnerable on-premises servers.
Netlas highlighted the incident as an example of patch bypass risk: applying a vendor update may not fully remove an underlying vulnerable condition when the fix is incomplete. Organizations running SharePoint Server should verify that they have deployed Microsoft’s superseding security updates, review internet-exposed SharePoint assets, and investigate for indications of compromise rather than treating the original patch alone as sufficient remediation.

See which actors are running it and whether you're in range.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.