Analyzing Sharepoint Exploits (CVE-2025-53770, CVE-2025-53771), (Wed, Jul 23rd)
ID: 967ae867-87d5-5d6b-951d-79b60950ea8f
STIX ID: report--967ae867-87d5-5d6b-951d-79b60950ea8f
Feed Name: SANS ISC Diary
Threat Score
This SANS write-up analyzes active exploit attempts targeting SharePoint (CVE-2025-53771) which use ToolPane.aspx to deliver a .NET deserialization payload that ultimately creates spinstall0.aspx; that page reveals the system MachineKey, allowing attackers to sign forged ViewState data and gain unauthorized access — the report includes decoded payloads, exploitation indicators, and remediation advice (rotate MachineKeys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
