SharePoint Vulnerabilities (CVE-2025-53770 & CVE-2025-53771): Everything You Need to Know
ID: 40794067-18f1-56e3-a345-df2a2e5a3612
STIX ID: report--40794067-18f1-56e3-a345-df2a2e5a3612
Feed Name: Wiz Blog
Microsoft issued emergency guidance for two chained zero-day vulnerabilities (CVE-2025-53770 — critical unsafe deserialization RCE — and CVE-2025-53771 — header spoofing) affecting on‑premises SharePoint servers; the ToolShell exploit chain has been observed in the wild dropping an ASPX web shell, extracting machineKey values to forge ViewState payloads for unauthenticated RCE, and includes indicators (spinstall0.aspx, SHA256 hash, IP addresses) and mitigation steps including emergency patches and temporary workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
