logo

CVE-2025-53770: Critical Unauthenticated RCE in Microsoft SharePoint

ID: 08e3e200-3704-5448-8ae4-6e21c60b9364

STIX ID: report--08e3e200-3704-5448-8ae4-6e21c60b9364

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-07-21

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

Microsoft and CISA confirmed active exploitation of CVE-2025-53770 — a critical, unauthenticated SharePoint Server RCE (ToolShell) that abuses /_layouts/15/ToolPane.aspx with a forged Referer to bypass authentication, uploads a malicious .aspx to leak machine keys, and then achieves RCE via signed __VIEWSTATE payloads; Microsoft released guidance and patches and CISA added the CVE to its KEV catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.