CVE-2025-53770 — Microsoft SharePoint Server Remote Code Execution Vulnerability
Executive Summary
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft SharePoint Enterprise Server 2016 5002760 (Security Update) 5002759 (Security Update) Critical Remote Code Execution 5002743 Base: 9.8 Temporal: 9.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C 16.0.5513.1001 Maybe None Microsoft SharePoint Server 2019 5002754 (Security Update) 5002753 (Security Update) Critical Remote Code Execution 5002739 Base: 9.8 Temporal: 9.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C 16.0.10417.20037 Maybe None Microsoft SharePoint Server Subscription Edition | 5002768 (Security Update) |
Critical | Remote Code Execution | Maybe |
Patches
| Article | Type | Restart |
|---|---|---|
5002768 |
Security Update | Maybe |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| soltanali0/CVE-2025-53770-Exploit | 315 | 2025-07-21 | SharePoint WebPart Injection Exploit Tool |
| MuhammadWaseem29/CVE-2025-53770 | 59 | 2025-07-22 | Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770) |
| hazcod/CVE-2025-53770 | 46 | 2025-07-21 | Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability. |
| kaizensecurity/CVE-2025-53770 | 43 | 2025-07-21 | POC |
| ZephrFish/CVE-2025-53770-Scanner | 18 | 2025-07-21 | ToolShell scanner - CVE-2025-53770 and detection information |
| 3a7/CVE-2025-53770 | 15 | 2025-07-27 | CVE-2025-53770 Mass Scanner |
| AdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE | 11 | 2025-07-22 | A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706. |
| exfil0/CVE-2025-53770 | 5 | 2025-07-23 | A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server |
| Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC | 4 | 2025-07-29 | |
| saladin0x1/CVE-2025-53770 | 4 | 2025-09-04 | |
| Bluefire-Redteam-Cybersecurity/bluefire-sharepoint-cve-2025-53770 | 3 | 2025-07-21 | |
| Sec-Dan/CVE-2025-53770-Scanner | 3 | 2025-07-22 | A Python-based reconnaissance scanner for safely identifying potential exposure to SharePoint vulnerability CVE-2025-53770. |
| Rabbitbong/OurSharePoint-CVE-2025-53770 | 2 | 2025-07-24 | Do you really think SharePoint is safe? |
| 0xKr1x/CVE-2025-53770-Scanner | 2 | 2025-07-28 | 🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer. |
| paolokappa/SharePointSecurityMonitor | 1 | 2025-07-21 | A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and automated alerting capabilities. |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 4
Nuclei templates 1
nuclei -id CVE-2025-53770
Acknowledgments
Viettel Cyber Security with Trend Zero Day Initiative
khoadha