logo

Analyzing Sharepoint Exploits (CVE-2025-53770, CVE-2025-53771), (Wed, Jul 23rd)

ID: 967ae867-87d5-5d6b-951d-79b60950ea8f

STIX ID: report--967ae867-87d5-5d6b-951d-79b60950ea8f

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-04-19

...
...

This SANS write-up analyzes active exploit attempts targeting SharePoint (CVE-2025-53771) which use ToolPane.aspx to deliver a .NET deserialization payload that ultimately creates spinstall0.aspx; that page reveals the system MachineKey, allowing attackers to sign forged ViewState data and gain unauthorized access — the report includes decoded payloads, exploitation indicators, and remediation advice (rotate MachineKeys).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.