logo

CVE-2025-53770: What Security Teams Need to Know About the SharePoint RCE Vulnerability

ID: 27a476b1-c606-5cec-934d-916a935fbc05

STIX ID: report--27a476b1-c606-5cec-934d-916a935fbc05

Feed Name: HackerOne Blog

Threat Score
85/100

Date Published: 2025-07-23

Date Updated: 2026-06-12

...
...

A critical remote code execution vulnerability (CVE-2025-53770) in on‑premises Microsoft SharePoint Server is being actively exploited by multiple threat groups, including nation-state actors; the flaw can allow attackers to run arbitrary code, steal cryptographic machine keys for persistence and lateral movement, and has public PoCs. Microsoft released a patch and the report recommends immediate patching, rotating ASP.NET machine keys, enabling AMSI, deploying endpoint detection, and conducting threat hunting using published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.