CVE-2025-53770: Critical Unauthenticated RCE in Microsoft SharePoint
ID: 08e3e200-3704-5448-8ae4-6e21c60b9364
STIX ID: report--08e3e200-3704-5448-8ae4-6e21c60b9364
Feed Name: Resources-2
Date Published: 2025-07-21
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
Microsoft and CISA confirmed active exploitation of CVE-2025-53770 — a critical, unauthenticated SharePoint Server RCE (ToolShell) that abuses /_layouts/15/ToolPane.aspx with a forged Referer to bypass authentication, uploads a malicious .aspx to leak machine keys, and then achieves RCE via signed __VIEWSTATE payloads; Microsoft released guidance and patches and CISA added the CVE to its KEV catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
