ACSC Warns Of SharePoint Vulnerability CVE-2025-53770
ID: 5b4cd4e3-28df-51ec-997c-0ef77b2b11dc
STIX ID: report--5b4cd4e3-28df-51ec-997c-0ef77b2b11dc
Feed Name: Cyble Blog
The Australian Cyber Security Centre and Microsoft warn of an actively exploited deserialization vulnerability (CVE-2025-53770) in on‑premises Microsoft SharePoint Server (affecting SharePoint Server 2016, 2019 and Subscription Edition). Microsoft released emergency updates in July 2025 and the advisory provides mitigation steps (apply updates, enable AMSI/Defender, rotate ASP.NET machine keys, restart IIS or isolate servers), detection queries, and IOCs such as spinstall0.aspx and w3wp.exe spawning encoded PowerShell to help defenders identify and respond to exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
