← back
CVE-2025-53770

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-502
In short

Microsoft SharePoint Server has a critical flaw where it processes untrusted data in a way that allows attackers to run malicious code remotely without authorization. This is a severe security issue because it can be exploited over the internet to take full control of affected servers.

Technical detail

CVE-2025-53770 is an unsafe deserialization vulnerability (CWE-502) in on-premises Microsoft SharePoint Server that permits unauthenticated remote code execution. Attackers can exploit this by sending specially crafted network requests containing malicious serialized objects; the server deserializes untrusted input without proper validation, leading to arbitrary code execution with server privileges. Active exploitation has been reported in the wild.

Summary generated and translated by AI from the official description.
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C
public PoCs found45
githubgithub.com/soltanali0/CVE-2025-53770-Exploit310githubgithub.com/MuhammadWaseem29/CVE-2025-5377058githubgithub.com/hazcod/CVE-2025-5377045githubgithub.com/kaizensecurity/CVE-2025-5377043githubgithub.com/ZephrFish/CVE-2025-53770-Scanner18githubgithub.com/3a7/CVE-2025-5377015githubgithub.com/AdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE11githubgithub.com/exfil0/CVE-2025-537705githubgithub.com/Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC4githubgithub.com/saladin0x1/CVE-2025-537704githubgithub.com/Bluefire-Redteam-Cybersecurity/bluefire-sharepoint-cve-2025-537703githubgithub.com/Sec-Dan/CVE-2025-53770-Scanner2githubgithub.com/Rabbitbong/OurSharePoint-CVE-2025-537702githubgithub.com/harryhaxor/CVE-2025-53770-SharePoint-Deserialization-RCE-PoC1githubgithub.com/imbas007/CVE-2025-53770-Vulnerable-Scanner1githubgithub.com/paolokappa/SharePointSecurityMonitor1githubgithub.com/Cameloo1/sharepoint-toolshell-micro-postmortem1githubgithub.com/tripoloski1337/CVE-2025-53770-scanner1githubgithub.com/grupooruss/CVE-2025-53770-Checker1githubgithub.com/Zedocun/SharePoint-ToolShell-CVE-2025-53770-Incident-Analysis1githubgithub.com/Udyz/CVE-2025-53770-Exploit1githubgithub.com/J4ck3LSyN-Gen2/CVE-2025-537700githubgithub.com/doerrdan/it-sec-toolshell0githubgithub.com/CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend0githubgithub.com/RukshanaAlikhan/CVE-2025-537700githubgithub.com/yosasasutsut/Blackash-CVE-2025-537700githubgithub.com/gmh5225/ZeroPoint0githubgithub.com/siag-itsec/CVE-2025-53770-Hunting0githubgithub.com/GreenForceNetworks/Toolshell_CVE-2025-537700githubgithub.com/0xray5c68616e37/cve-2025-537700githubgithub.com/zach115th/ToolShellFinder0githubgithub.com/nisargsuthar/suricata-rule-CVE-2025-537700githubgithub.com/bharath-cyber-root/sharepoint-toolshell-cve-2025-537700githubgithub.com/bitsalv/ToolShell-Honeypot0githubgithub.com/BirdsAreFlyingCameras/CVE-2025-53770_Raw-HTTP-Request-Generator0githubgithub.com/bossnick98/-SOC342---CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-and-RCE0githubgithub.com/r3xbugbounty/CVE-2025-537700githubgithub.com/daryllundy/CVE-2025-537700githubgithub.com/0xisfet/CVE-2025-53770-Scanner0githubgithub.com/Agampreet-Singh/CVE-2025-537700githubgithub.com/ghostn4444/CVE-2025-537700githubgithub.com/Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell0githubgithub.com/victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-3200githubgithub.com/rbctee/CVE-2025-537700exploitdbwww.exploit-db.com/exploits/52405unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →