← volver
CVE-2025-53770

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-502
En resumen

Microsoft SharePoint Server tiene una falla crítica donde procesa datos no confiables de forma insegura, permitiendo que atacantes ejecuten código malicioso remotamente sin autorización. Este es un problema grave de seguridad porque puede ser explotado a través de internet para tomar control total de los servidores afectados.

Detalle técnico

CVE-2025-53770 es una vulnerabilidad de deserialización insegura (CWE-502) en Microsoft SharePoint Server local que permite ejecución remota de código sin autenticación. Los atacantes pueden explotarla enviando solicitudes de red especialmente elaboradas con objetos serializados maliciosos; el servidor deserializa entrada no confiable sin validación apropiada, resultando en ejecución de código arbitrario con privilegios de servidor. Se ha reportado explotación activa en la naturaleza.

Resumen generado y traducido por IA a partir de la descripción oficial.
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C
PoCs públicas encontradas45
githubgithub.com/soltanali0/CVE-2025-53770-Exploit310githubgithub.com/MuhammadWaseem29/CVE-2025-5377058githubgithub.com/hazcod/CVE-2025-5377045githubgithub.com/kaizensecurity/CVE-2025-5377043githubgithub.com/ZephrFish/CVE-2025-53770-Scanner18githubgithub.com/3a7/CVE-2025-5377015githubgithub.com/AdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE11githubgithub.com/exfil0/CVE-2025-537705githubgithub.com/Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC4githubgithub.com/saladin0x1/CVE-2025-537704githubgithub.com/Bluefire-Redteam-Cybersecurity/bluefire-sharepoint-cve-2025-537703githubgithub.com/Sec-Dan/CVE-2025-53770-Scanner2githubgithub.com/Rabbitbong/OurSharePoint-CVE-2025-537702githubgithub.com/harryhaxor/CVE-2025-53770-SharePoint-Deserialization-RCE-PoC1githubgithub.com/imbas007/CVE-2025-53770-Vulnerable-Scanner1githubgithub.com/paolokappa/SharePointSecurityMonitor1githubgithub.com/Cameloo1/sharepoint-toolshell-micro-postmortem1githubgithub.com/tripoloski1337/CVE-2025-53770-scanner1githubgithub.com/grupooruss/CVE-2025-53770-Checker1githubgithub.com/Zedocun/SharePoint-ToolShell-CVE-2025-53770-Incident-Analysis1githubgithub.com/Udyz/CVE-2025-53770-Exploit1githubgithub.com/J4ck3LSyN-Gen2/CVE-2025-537700githubgithub.com/doerrdan/it-sec-toolshell0githubgithub.com/CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend0githubgithub.com/RukshanaAlikhan/CVE-2025-537700githubgithub.com/yosasasutsut/Blackash-CVE-2025-537700githubgithub.com/gmh5225/ZeroPoint0githubgithub.com/siag-itsec/CVE-2025-53770-Hunting0githubgithub.com/GreenForceNetworks/Toolshell_CVE-2025-537700githubgithub.com/0xray5c68616e37/cve-2025-537700githubgithub.com/zach115th/ToolShellFinder0githubgithub.com/nisargsuthar/suricata-rule-CVE-2025-537700githubgithub.com/bharath-cyber-root/sharepoint-toolshell-cve-2025-537700githubgithub.com/bitsalv/ToolShell-Honeypot0githubgithub.com/BirdsAreFlyingCameras/CVE-2025-53770_Raw-HTTP-Request-Generator0githubgithub.com/bossnick98/-SOC342---CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-and-RCE0githubgithub.com/r3xbugbounty/CVE-2025-537700githubgithub.com/daryllundy/CVE-2025-537700githubgithub.com/0xisfet/CVE-2025-53770-Scanner0githubgithub.com/Agampreet-Singh/CVE-2025-537700githubgithub.com/ghostn4444/CVE-2025-537700githubgithub.com/Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell0githubgithub.com/victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-3200githubgithub.com/rbctee/CVE-2025-537700exploitdbwww.exploit-db.com/exploits/52405no verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →