CVE-2025-53770

Published Jul 20, 2025

Last updated a month ago

Exploit knownCVSS critical 9.8
Microsoft SharePoint
ToolShell

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-53770 involves a deserialization of untrusted data vulnerability within on-premises Microsoft SharePoint Server. This flaw allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for this vulnerability is currently in the wild. Microsoft is actively preparing and testing a comprehensive update to address CVE-2025-53770. In the meantime, it is recommended that organizations review and apply the mitigations specified in Microsoft's CVE documentation to protect against potential exploitation.

Description
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Insights

Analysis from the Intruder Security Team
Published Jul 21, 2025 Updated Jul 23, 2025

This is a critical remote code execution vulnerability in Sharepoint when used on-prem - Sharepoint for Microsoft 365 is not affected. It is a variant of a previous bug which, in combination with CVE-2025-53771, allows an unauthenticated attacker to use a deserialization vulnerability to run code on the server.

If you host a Sharepoint instance you should immediately apply the security update and review the advice on this Microsoft page. Paying particular attention to the sections describing how to rotate your Machine Key and detect if you were already compromised.

As there was a lag time between information on this vulnerability being available to attackers and the availability of the patch, there has been active exploitation of Sharepoint instances during this period.

We have deployed an active check (11am 22nd July) and set off an Emerging Threat Scan for all of our Enterprise customers. In addition, we are committing this to the public Nuclei templates repository so that you can check your systems via Intruder - or for free via Nuclei as soon as the request is merged.

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Exploit added on
Jul 20, 2025
Exploit action due
Jul 21, 2025
Required action
Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

12

  1. 【アーカイブ】 SharePointの脆弱性と対策について詳しく解説! SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/NCC59MrmLD #cybernote #ブログ仲間と繋がりたい #Web

    @Teeeda_worker

    9 Sept 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +25.40% - CVE-2023-20269 (ASA..) +24.24% - CVE-2023-20269 (FTD..) +24.24% - CVE-2024-26169 (Windows Error R..) +9.58% - CVE-2022-27510 (NetScaler ADC..) +6.76%

    @DefusedCyber

    8 Sept 2025

    5121 Impressions

    9 Retweets

    43 Likes

    18 Bookmarks

    2 Replies

    2 Quotes

  3. A critical RCE flaw in Microsoft SharePoint Server 2019 (CVE-2025-53770) puts enterprise systems at risk. Learn the impact and how to defend. https://t.co/3Rd9omYRix #CyberSecurity #SharePoint #Microsoft #CVE202553770 #RemoteCodeExecution #EnterpriseSecurity https://t.co/sFNSNt

    @redsecuretech

    7 Sept 2025

    53 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  4. 📢 New CVE analysis just dropped! CVE-2025-53770 enables full remote takeover of SharePoint servers—see how it works, who's exploiting it, and how to patch it fast. 🔗 Read the full breakdown → https://t.co/lSxXcPYLUa Stay safe, and let us know your thoughts!

    @PurpleOps_io

    7 Sept 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 【アーカイブ】 SharePointの脆弱性対策を徹底解説!詳細を確認し安全を守ろう。 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abmNUx #cybernote #ブログ仲間

    @CyberNote_media

    5 Sept 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Trellix researchers look into a recent wave of exploitation targeting ToolShell vulnerabilities in Microsoft SharePoint Server (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). https://t.co/oeIcaLYlcX https://t.co/SSiUr8XHAN

    @virusbtn

    5 Sept 2025

    1402 Impressions

    7 Retweets

    29 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  7. 【アーカイブ】 最新のゼロデイ脆弱性情報と対策法を解説。企業必読! SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abmNUx #cybernote #ブログ仲間と繋が

    @CyberNote_media

    4 Sept 2025

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 【アーカイブ】 最新の脆弱性情報と対策を詳しく解説します! SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abmNUx #cybernote #ブログ仲間と繋がりたい #Web

    @CyberNote_media

    4 Sept 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 【アーカイブ】 最新の脆弱性情報と有効な対策を詳しく解説!必読です。 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/NCC59MrmLD #cybernote #ブログ仲間と繋

    @Teeeda_worker

    3 Sept 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【アーカイブ】 SharePointのゼロデイ脆弱性の概要と対策を詳しく解説します! SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/NCC59MrUBb #cybernote #ブログ仲間と

    @Teeeda_worker

    3 Sept 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 【アーカイブ】 最新の脆弱性とその対策を徹底解説!必見です。 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abmNUx #cybernote #ブログ仲間と繋がりたい #

    @CyberNote_media

    2 Sept 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +426.22% - CVE-2024-42057 (Zyxel Firewall..) +29.73% - CVE-2021-21974 (ESXi..) +25.27% - CVE-2018-13374 (FortiOS..) +15.68% - CVE-2020-3259 (ASA..) +11.25%

    @DefusedCyber

    1 Sept 2025

    4835 Impressions

    2 Retweets

    14 Likes

    9 Bookmarks

    0 Replies

    2 Quotes

  13. ⚠️ Weekly vuln radar. https://t.co/Cd6L8ACyLV – spot what’s trending before it’s everywhere: CVE-2025-53770 CVE-2025-43300 CVE-2025-5777 CVE-2024-21887 CVE-2023-46604 (@ThreatBookLabs) CVE-2025-7776 CVE-2025-54309 CVE-2025-7775 CVE-2025-53771 https://t.co/q4Rx5wWFSt

    @ptdbugs

    29 Aug 2025

    286 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 The SharePoint breach (CVE-2025-53770) has hit hundreds of orgs. Guest Ron Reiter of Sentra + Joe Saunders of RunSafe explain why IT failures spill into OT — and why patching isn’t enough. https://t.co/Uc2mYKuQjP https://t.co/yBZcS11Ws1

    @RunSafeSecurity

    28 Aug 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 【アーカイブ】 最新のSharePoint脆弱性についての解説と対策を紹介! SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abnlK5 #cybernote #ブログ仲間と繋がりた

    @CyberNote_media

    27 Aug 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. #VulnerabilityReport #CVE202553770 SharePoint Server Under Active Zero-Day Attack (CVE-2025-53770, CVSS 9.8), No Patch Yet! https://t.co/mmeqrlO2ka

    @Komodosec

    25 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +361.94% - CVE-2024-42057 (Zyxel Firewall..) +29.73% - CVE-2023-20269 (ASA..) +24.24% - CVE-2023-20269 (FTD..) +24.24% - CVE-2021-21974 (ESXi..) +16.07%

    @DefusedCyber

    25 Aug 2025

    936 Impressions

    1 Retweet

    14 Likes

    5 Bookmarks

    0 Replies

    1 Quote

  18. 🚨 ZERO-DAY ALERT: SharePoint “ToolShell” Exploit in Active Use ⚠️ • CVE-2025-53770 → unauthenticated RCE on SharePoint (2016/2019/SE) • Attackers persist by stealing machine keys 🔑 • Victims include gov, energy, healthcare, telecom , even the U.S. DOE &am

    @Newtalics

    25 Aug 2025

    80 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 【アーカイブ】 最新のSharePoint脆弱性の詳細と対策を解説! SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/NCC59MrmLD #cybernote #ブログ仲間と繋がりたい #Webラ

    @Teeeda_worker

    24 Aug 2025

    151 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. A zero-day RCE in SharePoint_FileStorage.dll (CVE-2025-53770) was exploited to deploy WarLock ransomware on Colt Technology Services’ SharePoint, enabling SYSTEM access and lateral movement using ToolShell and LOLBins. #WarLock #ZeroDay #Colt https://t.co/AxJilCBivd

    @TweetThreatNews

    24 Aug 2025

    294 Impressions

    1 Retweet

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  21. Actively exploited CVE : CVE-2025-53770

    @transilienceai

    24 Aug 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. https://t.co/d7IvjGeOtG The newly discovered CVE-2025-53770 ‘ToolShell’ vulnerability is wreaking havoc on Microsoft SharePoint servers. In this video, we explain how this exploit works, its global impact, and perform a SOC-style analysis using LetsDefend to demonstrate ho

    @ManMotasem

    23 Aug 2025

    94 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Actively exploited CVE : CVE-2025-53770

    @transilienceai

    23 Aug 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  24. New IOC Alert → Defending Against ToolShell: SharePoint's Latest Critical Vulnerability. ■ Indicator: CVE-2025-53770

    @CTI131

    23 Aug 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 【アーカイブ】 注目の最新脆弱性!早急な対策が必要です。 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abmNUx #cybernote #ブログ仲間と繋がりたい #Webラ

    @CyberNote_media

    22 Aug 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. #Proactive #Security for CVE-2025-53770 and CVE-2025-53771 #SharePoint_Attacks https://t.co/tloLD9OPvK https://t.co/hcUdHNHgIF

    @omvapt

    22 Aug 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. #Proactive_Security for CVE-2025-53770 and CVE-2025-53771 #SharePoint_Attacks https://t.co/bC4ahVz4UO https://t.co/0kySI9Tg2R

    @omvapt

    21 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771 - also known as the SharePoint Zero Days - allow unauthenticated attackers to seize control of servers, steal cryptographic keys, and plant persistent backdoors. What started as 75 confirmed breaches has now grown to 400+ https://t.co

    @ExtraHop

    21 Aug 2025

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. New IOC Alert → CVE-2025-53770 and CVE-2025-53771: Actively Exploited SharePoint Vulnerabilities. ■ Indicator: CVE-2025-49704

    @CTI131

    21 Aug 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. New IOC Alert → SharePoint Vulnerabilities (CVE-2025-53770 & CVE-2025-53771): Everything You Need to Know. ■ Indicator: CVE-2025-23266

    @CTI131

    20 Aug 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 【アーカイブ】 最新の脆弱性とその対策を詳しく解説!必読です。 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/NCC59MrUBb #cybernote #ブログ仲間と繋がりた

    @Teeeda_worker

    20 Aug 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 【アーカイブ】 SharePointの新たな脆弱性と対策を詳しく解説!企業必見です。 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/NCC59MrmLD #cybernote #ブログ仲間と

    @Teeeda_worker

    20 Aug 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. New IOC Alert → Toolshell: Large-scale exploitation of new SharePoint RCE vulnerability chain identified. ■ Indicator: CVE-2025-53770

    @CTI131

    20 Aug 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Actively exploited CVE : CVE-2025-53770

    @transilienceai

    20 Aug 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. 【漏洞工具】SharePoint 2025 RCE 图形化漏洞利用工具 相关 CVE 编号为: CVE-2025-53770 CVE-2025-53771 CVE-2025-49704 CVE-2025-49706 https://t.co/8DPcYBYCq4 https://t.co/lts8kW1swv

    @cybersecuritysl

    19 Aug 2025

    1260 Impressions

    7 Retweets

    18 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  36. Ah bah effectivement… ça n’aura pas traîné 😬 Plus de 400 serveurs #SharePoint déjà compromis via les zero-day CVE-2025-53770 & CVE-2025-53771, attribués à 3 groupes chinois 👉 https://t.co/hD2yQB1HML

    @Guardia_School

    19 Aug 2025

    37 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Actively exploited CVE : CVE-2025-53770

    @transilienceai

    19 Aug 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  38. Turn out CVE-2025-53770 is mine. I report it to MSRC after July patch released. @msftsecresponse say it OutofScope because I use the same deser payload at different endpoint which they weren’t aware of. I tried my best to mitigate the exploit and all I got is a thank, nice rewa

    @_l0gg

    19 Aug 2025

    8427 Impressions

    7 Retweets

    91 Likes

    24 Bookmarks

    2 Replies

    0 Quotes

  39. 【アーカイブ】 ゼロデイ脆弱性の概要と企業が取るべき対策を分かりやすく解説 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/EV97abmNUx #cybernote #ブログ仲

    @CyberNote_media

    19 Aug 2025

    12 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 🚨ALERT cybersecurity: Colt Technology Services Hit by Ransomware UK telecom Colt was attacked by the Warlock ransomware gang. Hosting, Colt Online & Voice APIs disrupted. Exploited SharePoint vuln (CVE-2025-53770); recovery underway. 🔗 Source: https://t.co/IP80GuE90p

    @The_SentinelX

    18 Aug 2025

    220 Impressions

    0 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  41. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +108108.75% - CVE-2023-20269 (ASA..) +58.41% - CVE-2023-20269 (FTD..) +58.41% - CVE-2024-42057 (Zyxel Firewall..) +29.73% - CVE-2024-37085 (ESXi..) +20.63%

    @DefusedCyber

    18 Aug 2025

    20187 Impressions

    30 Retweets

    184 Likes

    111 Bookmarks

    2 Replies

    1 Quote

  42. 【セキュリティニュース】 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://t.co/1TS3l1FAIg cybernote

    @BADBEAR112919

    18 Aug 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨💀 APT ALERT – WarLock ransomware hits Colt Attackers exploited SharePoint zero-day CVE-2025-53770 (ToolShell) to breach Colt Telecom. 📂 Stolen: customer, employee & internal data (samples already leaked) ⚡ Likely entry: RCE in on-prem SharePoint 🛡 Response

    @Newtalics

    17 Aug 2025

    109 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  44. 250817 insider info Critical SharePoint Zero-Day Exploit CVE-2025-53770 https://t.co/lJSlPcotoF

    @ZenoSloim

    17 Aug 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 12日、Colt Technology ServicesはWarLockランサムウェアグループによる標的型攻撃を受け、約100万件の機密データが漏洩。Microsoft SharePointのゼロデイ脆弱性(CVE-2025-53770)が悪用され、サービス停止とデータ窃取が発生し

    @shiroikoibitoa

    17 Aug 2025

    204 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Actively exploited CVE : CVE-2025-53770

    @transilienceai

    17 Aug 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  47. 🚨 ALERT: Hackers exploit Microsoft SharePoint flaw (CVE-2025-53770), breaching Canada’s House of Commons on Aug 9, stealing employee data. Is your system next? Fortify your defenses now! 🛡️ #CyberSecurity #CanadaBreach

    @TlISYZ19zJ47201

    16 Aug 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 🚨🔓 BREACH ALERT – Canadian Parliament hacked Zero-day CVE-2025-53770 “ToolShell” exploited in SharePoint → sensitive staff data stolen. 📂 Exposed: names, titles, office locations, emails + device mgmt details 🛡 Action: Patch ASAP + warn staff about phishing

    @Newtalics

    16 Aug 2025

    35 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Hackers exploited a critical Microsoft SharePoint zero-day (CVE-2025-53770) to breach Canada's House of Commons, exposing employee and device info. Investigations underway by CSE and House of Commons. #MicrosoftFlaw #CanadaSecurity #DataBreach https://t.co/fTw0hhf5Ns

    @TweetThreatNews

    15 Aug 2025

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. CVE-2025-53770: critical SharePoint vulnerability dubbed "ToolShell" https://t.co/kMakaLaG87

    @oxs127

    15 Aug 2025

    242 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

Configurations