AI description
CVE-2025-53771 is a spoofing vulnerability affecting Microsoft Office SharePoint. It stems from an improper limitation of a pathname to a restricted directory, also known as a 'path traversal'. This vulnerability allows an authorized attacker to perform spoofing over a network. The vulnerability exists in on-premises SharePoint Servers and does not impact SharePoint Online in Microsoft 365. Microsoft has released updates to address this vulnerability, with the update including more robust protections than previous updates for similar vulnerabilities. It is related to other SharePoint vulnerabilities like CVE-2025-49706, and can be chained with other vulnerabilities to achieve remote code execution.
- Description
- Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Source
- secure@microsoft.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 7.1
- Impact score
- 4.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Severity
- HIGH
- secure@microsoft.com
- CWE-20
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
53
Microsoft issues emergency patches for SharePoint Microsoft disclosed and patched two zero-day SharePoint flaws—CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771—actively exploited since July 18 in attacks dubbed “ToolShell.” CVE-2025-53770 allows unauthenticated remote code
@dCypherIO
22 Jul 2025
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Two critical vulnerabilities CVE-2025-53770 and CVE-2025-53771 target Microsoft SharePoint Servers allowing attackers to upload malicious files and extract cryptographic secrets. These flaws are evolved versions of previously patched issues CVE-2025-4970
@Tudorel92659164
22 Jul 2025
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ataque cibernético em massa afeta SharePoint on-premises. Hackers exploram falha zero-day (CVE-2025-53771) roubando chaves e instalando backdoors. Leia mais em : https://t.co/m7rjeKqAuH https://t.co/7CR77lLOvY
@dioprog44282
22 Jul 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Customer guidance for SharePoint vulnerability CVE-2025-53770 Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. https://t.co/2FrzZvhZmP https://t.co/1pk6aWhmP9
@OvidiuPismac
22 Jul 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Widespread ToolShell zero-day attacks exploiting CVE-2025-53770 and CVE-2025-53771 have targeted unpatched SharePoint servers globally since July, mainly threatening high-value organizations. Ongoing confusion persists over attack specifics. #ToolShell #… https://t.co/EaCQde1wD
@TweetThreatNews
22 Jul 2025
129 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Two critical zero-day vulnerabilities in on-premises Microsoft SharePoint (CVE-2025-53770 & CVE-2025-53771) are actively exploited via the ToolShell chain. Microsoft released emergency patches to address these bypass variants. #SharePoint #ZeroDay https://t.co/E2UITlBpKC
@TweetThreatNews
22 Jul 2025
168 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical vulnerabilities CVE-2025-53770 and CVE-2025-53771 in on-premise Microsoft SharePoint Servers enable unauthenticated remote code execution through deserialization and ViewState abuse. These flaws stem from incomplete patches. #SharePoint #CyberRisk https://t.co/uz2znldWxv
@TweetThreatNews
22 Jul 2025
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft released emergency patches on July 21, 2025, for two critical SharePoint vulnerabilities, CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771 (CVSS 6.3), affecting on-premises SharePoint Server 2019 and Subscription Edition, per Microsoft. Over 85 servers across 29 https://t
@LaszloRealtor
22 Jul 2025
166 Impressions
1 Retweet
1 Like
1 Bookmark
1 Reply
0 Quotes
#SharePoint: Microsoft releases emergency patches for widely exploited SharePoint Remote Code Execution vulnerabilities CVE-2025-53770 and CVE-2025-53771 (aka #ToolShell) - patch now! 👇 https://t.co/oNOZLumuEh
@securestep9
21 Jul 2025
235 Impressions
3 Retweets
4 Likes
3 Bookmarks
0 Replies
0 Quotes
🚨 Research update: #ToolShell is back, and it just leveled up. Two new vulnerabilities in Microsoft SharePoint Server, CVE-2025-53770 (RCE) and CVE-2025-53771 (auth bypass), are being actively exploited in the wild. 🔓 Attackers are chaining them to >> • Bypass aut
@wiz_io
21 Jul 2025
65 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
📌 Microsoft releases emergency security updates for SharePoint to fix two zero-day vulnerabilities (CVE-2025-53770 and CVE-2025-53771) exploited in global "ToolShell" attacks. #CyberSecurity #SharePoint https://t.co/TLr4I54nDv https://t.co/QgXUcvVd1P
@CyberHub_blog
21 Jul 2025
113 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
«Microsoft ha publicado actualizaciones de seguridad que protegen completamente a los clientes que usan SharePoint Subscription Edition y SharePoint 2019 contra los riesgos CVE-2025-53770 y CVE-2025-53771». (Inglés) Vía: @msftsecresponse, @jc_vazquez https://t.co/o5RJBcsI
@DragsterSystems
21 Jul 2025
125 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#ICYMI Microsoft publicó actualizaciones de seguridad urgentes para SharePoint para dos vulnerabilidades de día cero, identificadas como CVE-2025-53770 y CVE-2025-53771, que han comprometido servicios en todo el mundo mediante ataques "ToolShell". ⚠️ https://t.co/zpW0zKN0am
@rleon_mx
21 Jul 2025
166 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SECURITY ALERT: Two new Microsoft SharePoint On-Prem vulnerabilities — CVE-2025-53770 & CVE-2025-53771 — are being actively exploited in the wild. One is rated Critical (CVSS 9.8) and bypasses July’s patches. Meanwhile, Trend Micro offers proactive protection beyo
@TrendMicroRSRCH
21 Jul 2025
18915 Impressions
4 Retweets
11 Likes
0 Bookmarks
2 Replies
0 Quotes
🚨 Active Exploits Hit @Microsoft @SharePoint Servers New RCE zero-days CVE-2025-53770 & CVE-2025-53771 are being chained to hijack on-prem SharePoint instances globally. 🧵 • Exploits bypass July patches • CVE-2025-53770 = deserialization flaw • Used to steal Mac
@TechNadu
21 Jul 2025
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DoJ partner agencies report widespread SharePoint compromises across federal and energy sectors. CVE-2025-53770 and CVE-2025-53771 represent variants that bypass Microsoft's July Patch Tuesday fixes for the original "ToolShell" exploit chain demonstrated at Pwn2Own Berlin. CISA
@fs0c131y
21 Jul 2025
5148 Impressions
9 Retweets
18 Likes
11 Bookmarks
0 Replies
0 Quotes
Microsoft releases emergency patch: 0-day vulnerabilities in SharePoint used in RCE attacks Critical zero-day vulnerabilities in Microsoft SharePoint (CVE-2025-53770 and CVE-2025-53771) have been actively exploited since the end of last week, and at least 85 servers have been htt
@RedDogSecurity1
21 Jul 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: Microsoft releases emergency SharePoint patches for CVE-2025-53770 & CVE-2025-53771 📖 Full analysis: https://t.co/XquMN3Y43A 🎧 https://t.co/2UJ3S4KxTo #SharePoint #CyberSecurity #ZeroDay https://t.co/1Kv0ZWqcsk
@technijian_
21 Jul 2025
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Active exploits target a zero-day in on-premise SharePoint servers worldwide, risking persistent access and key theft. Microsoft issued patches for CVE-2025-53770 and CVE-2025-53771. Countries and organizations advised to act. #SharePointRisk #CyberAlert https://t.co/6k9fCPvGtv
@TweetThreatNews
21 Jul 2025
94 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Microsoft has now released emergency security updates that fully protect those using SharePoint Subscription Edition and SharePoint 2019 against the risks posed by CVE-2025-53770, and CVE-2025-53771. UPDATE NOW!! https://t.co/MyoAtLQRPp https://t.co/07vFpriHQr
@helloitsliam
21 Jul 2025
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft выпускает экстренный патч: 0-day уязвимости в SharePoint использовались в RCE-атаках Обнаружено, что критические уязвимости нулевого дня в Microsoft SharePoint (CVE-202
@pc7ooo
21 Jul 2025
117 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Consultez le dernier article de ma newsletter : 🚨 ALERTE DE SÉCURITÉ – Failles critiques sur SharePoint Server (CVE-2025-53770 et CVE-2025-53771) https://t.co/pM5n1bpfr5 via @LinkedIn
@KaderBila
21 Jul 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft has issued a security update for SharePoint Subscription Edition which mitigates CVE-2025-53770 and CVE-2025-53771. Defenders should apply the update immediately.🫡 #Cybersecurity #Sharepoint #toolshell https://t.co/yBdKOyMZts https://t.co/8U5nNsUWCQ
@0x534c
21 Jul 2025
45 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Do you manage an on-prem SharePoint server? Critical 0-day under mass exploitation - patch now Read more: https://t.co/lsPthuAucK 1. Active zero-day attacks targeting on-premises SharePoint servers via CVE-2025-53770 and CVE-2025-53771. 2. Apply security updates https://t
@The_Cyber_News
21 Jul 2025
745 Impressions
1 Retweet
12 Likes
1 Bookmark
0 Replies
2 Quotes
CVE-2025-53771 Microsoft SharePoint Server Spoofing Vulnerability https://t.co/KUJ5zDtREA #cyberrisk #cybersecurity
@SecQube
21 Jul 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📢 ALERT: Microsoft warns of active attacks exploiting a zero-day flaw in on-premises #SharePoint servers (CVE-2025-53770 & CVE-2025-53771). No patch yet for some versions, advises disconnecting servers from the internet if unable to enable recommended malware protection.
@NewsNucleus
21 Jul 2025
563 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
1 Quote
📌 أصدرت مايكروسوفت تحديثات طارئة لأمان SharePoint لمعالجة ثغرتين بخاصة، وهما CVE-2025-53770 وCVE-2025-53771، اللتين استُغلتا في هجمات "ToolShell" وأثرت على الخدمات على مستوى ا
@Cybercachear
21 Jul 2025
162 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft has released security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 against the risks posed by CVE-2025-53770, and CVE-2025-53771. These vulnerabilities apply to on-premises SharePoint Servers only. Customers should apply
@msftsecresponse
21 Jul 2025
38237 Impressions
44 Retweets
101 Likes
26 Bookmarks
3 Replies
8 Quotes
CVE-2025-53771 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a… https://t.co/ntyEKRjF51
@CVEnew
20 Jul 2025
556 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes