CVE-2025-53771

Published Jul 20, 2025

Last updated an hour ago

CVSS high 7.1
Microsoft SharePoint

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-53771 is a spoofing vulnerability affecting Microsoft Office SharePoint. It stems from an improper limitation of a pathname to a restricted directory, also known as a 'path traversal'. This vulnerability allows an authorized attacker to perform spoofing over a network. The vulnerability exists in on-premises SharePoint Servers and does not impact SharePoint Online in Microsoft 365. Microsoft has released updates to address this vulnerability, with the update including more robust protections than previous updates for similar vulnerabilities. It is related to other SharePoint vulnerabilities like CVE-2025-49706, and can be chained with other vulnerabilities to achieve remote code execution.

Description
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Source
secure@microsoft.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
7.1
Impact score
4.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

53

  1. Microsoft issues emergency patches for SharePoint Microsoft disclosed and patched two zero-day SharePoint flaws—CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771—actively exploited since July 18 in attacks dubbed “ToolShell.” CVE-2025-53770 allows unauthenticated remote code

    @dCypherIO

    22 Jul 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Two critical vulnerabilities CVE-2025-53770 and CVE-2025-53771 target Microsoft SharePoint Servers allowing attackers to upload malicious files and extract cryptographic secrets. These flaws are evolved versions of previously patched issues CVE-2025-4970

    @Tudorel92659164

    22 Jul 2025

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Ataque cibernético em massa afeta SharePoint on-premises. Hackers exploram falha zero-day (CVE-2025-53771) roubando chaves e instalando backdoors. Leia mais em : https://t.co/m7rjeKqAuH https://t.co/7CR77lLOvY

    @dioprog44282

    22 Jul 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Customer guidance for SharePoint vulnerability CVE-2025-53770 Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. https://t.co/2FrzZvhZmP https://t.co/1pk6aWhmP9

    @OvidiuPismac

    22 Jul 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Widespread ToolShell zero-day attacks exploiting CVE-2025-53770 and CVE-2025-53771 have targeted unpatched SharePoint servers globally since July, mainly threatening high-value organizations. Ongoing confusion persists over attack specifics. #ToolShell #… https://t.co/EaCQde1wD

    @TweetThreatNews

    22 Jul 2025

    129 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Two critical zero-day vulnerabilities in on-premises Microsoft SharePoint (CVE-2025-53770 & CVE-2025-53771) are actively exploited via the ToolShell chain. Microsoft released emergency patches to address these bypass variants. #SharePoint #ZeroDay https://t.co/E2UITlBpKC

    @TweetThreatNews

    22 Jul 2025

    168 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Critical vulnerabilities CVE-2025-53770 and CVE-2025-53771 in on-premise Microsoft SharePoint Servers enable unauthenticated remote code execution through deserialization and ViewState abuse. These flaws stem from incomplete patches. #SharePoint #CyberRisk https://t.co/uz2znldWxv

    @TweetThreatNews

    22 Jul 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Microsoft released emergency patches on July 21, 2025, for two critical SharePoint vulnerabilities, CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771 (CVSS 6.3), affecting on-premises SharePoint Server 2019 and Subscription Edition, per Microsoft. Over 85 servers across 29 https://t

    @LaszloRealtor

    22 Jul 2025

    166 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  9. #SharePoint: Microsoft releases emergency patches for widely exploited SharePoint Remote Code Execution vulnerabilities CVE-2025-53770 and CVE-2025-53771 (aka #ToolShell) - patch now! 👇 https://t.co/oNOZLumuEh

    @securestep9

    21 Jul 2025

    235 Impressions

    3 Retweets

    4 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Research update: #ToolShell is back, and it just leveled up. Two new vulnerabilities in Microsoft SharePoint Server, CVE-2025-53770 (RCE) and CVE-2025-53771 (auth bypass), are being actively exploited in the wild. 🔓 Attackers are chaining them to >> • Bypass aut

    @wiz_io

    21 Jul 2025

    65 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 📌 Microsoft releases emergency security updates for SharePoint to fix two zero-day vulnerabilities (CVE-2025-53770 and CVE-2025-53771) exploited in global "ToolShell" attacks. #CyberSecurity #SharePoint https://t.co/TLr4I54nDv https://t.co/QgXUcvVd1P

    @CyberHub_blog

    21 Jul 2025

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. «Microsoft ha publicado actualizaciones de seguridad que protegen completamente a los clientes que usan SharePoint Subscription Edition y SharePoint 2019 contra los riesgos CVE-2025-53770 y CVE-2025-53771». (Inglés) Vía: @msftsecresponse, @jc_vazquez https://t.co/o5RJBcsI

    @DragsterSystems

    21 Jul 2025

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. #ICYMI Microsoft publicó actualizaciones de seguridad urgentes para SharePoint para dos vulnerabilidades de día cero, identificadas como CVE-2025-53770 y CVE-2025-53771, que han comprometido servicios en todo el mundo mediante ataques "ToolShell". ⚠️ https://t.co/zpW0zKN0am

    @rleon_mx

    21 Jul 2025

    166 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 SECURITY ALERT: Two new Microsoft SharePoint On-Prem vulnerabilities — CVE-2025-53770 & CVE-2025-53771 — are being actively exploited in the wild. One is rated Critical (CVSS 9.8) and bypasses July’s patches. Meanwhile, Trend Micro offers proactive protection beyo

    @TrendMicroRSRCH

    21 Jul 2025

    18915 Impressions

    4 Retweets

    11 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  15. 🚨 Active Exploits Hit @Microsoft @SharePoint Servers New RCE zero-days CVE-2025-53770 & CVE-2025-53771 are being chained to hijack on-prem SharePoint instances globally. 🧵 • Exploits bypass July patches • CVE-2025-53770 = deserialization flaw • Used to steal Mac

    @TechNadu

    21 Jul 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. DoJ partner agencies report widespread SharePoint compromises across federal and energy sectors. CVE-2025-53770 and CVE-2025-53771 represent variants that bypass Microsoft's July Patch Tuesday fixes for the original "ToolShell" exploit chain demonstrated at Pwn2Own Berlin. CISA

    @fs0c131y

    21 Jul 2025

    5148 Impressions

    9 Retweets

    18 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  17. Microsoft releases emergency patch: 0-day vulnerabilities in SharePoint used in RCE attacks Critical zero-day vulnerabilities in Microsoft SharePoint (CVE-2025-53770 and CVE-2025-53771) have been actively exploited since the end of last week, and at least 85 servers have been htt

    @RedDogSecurity1

    21 Jul 2025

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 CRITICAL: Microsoft releases emergency SharePoint patches for CVE-2025-53770 & CVE-2025-53771 📖 Full analysis: https://t.co/XquMN3Y43A 🎧 https://t.co/2UJ3S4KxTo #SharePoint #CyberSecurity #ZeroDay https://t.co/1Kv0ZWqcsk

    @technijian_

    21 Jul 2025

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Active exploits target a zero-day in on-premise SharePoint servers worldwide, risking persistent access and key theft. Microsoft issued patches for CVE-2025-53770 and CVE-2025-53771. Countries and organizations advised to act. #SharePointRisk #CyberAlert https://t.co/6k9fCPvGtv

    @TweetThreatNews

    21 Jul 2025

    94 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  20. Microsoft has now released emergency security updates that fully protect those using SharePoint Subscription Edition and SharePoint 2019 against the risks posed by CVE-2025-53770, and CVE-2025-53771. UPDATE NOW!! https://t.co/MyoAtLQRPp https://t.co/07vFpriHQr

    @helloitsliam

    21 Jul 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Microsoft выпускает экстренный патч: 0-day уязвимости в SharePoint использовались в RCE-атаках Обнаружено, что критические уязвимости нулевого дня в Microsoft SharePoint (CVE-202

    @pc7ooo

    21 Jul 2025

    117 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Consultez le dernier article de ma newsletter : 🚨 ALERTE DE SÉCURITÉ – Failles critiques sur SharePoint Server (CVE-2025-53770 et CVE-2025-53771) https://t.co/pM5n1bpfr5 via @LinkedIn

    @KaderBila

    21 Jul 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Microsoft has issued a security update for SharePoint Subscription Edition which mitigates CVE-2025-53770 and CVE-2025-53771. Defenders should apply the update immediately.🫡 #Cybersecurity #Sharepoint #toolshell https://t.co/yBdKOyMZts https://t.co/8U5nNsUWCQ

    @0x534c

    21 Jul 2025

    45 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 Do you manage an on-prem SharePoint server? Critical 0-day under mass exploitation - patch now Read more: https://t.co/lsPthuAucK 1. Active zero-day attacks targeting on-premises SharePoint servers via CVE-2025-53770 and CVE-2025-53771. 2. Apply security updates https://t

    @The_Cyber_News

    21 Jul 2025

    745 Impressions

    1 Retweet

    12 Likes

    1 Bookmark

    0 Replies

    2 Quotes

  25. CVE-2025-53771 Microsoft SharePoint Server Spoofing Vulnerability https://t.co/KUJ5zDtREA #cyberrisk #cybersecurity

    @SecQube

    21 Jul 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 📢 ALERT: Microsoft warns of active attacks exploiting a zero-day flaw in on-premises #SharePoint servers (CVE-2025-53770 & CVE-2025-53771). No patch yet for some versions, advises disconnecting servers from the internet if unable to enable recommended malware protection.

    @NewsNucleus

    21 Jul 2025

    563 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  27. 📌 أصدرت مايكروسوفت تحديثات طارئة لأمان SharePoint لمعالجة ثغرتين بخاصة، وهما CVE-2025-53770 وCVE-2025-53771، اللتين استُغلتا في هجمات "ToolShell" وأثرت على الخدمات على مستوى ا

    @Cybercachear

    21 Jul 2025

    162 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Microsoft has released security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 against the risks posed by CVE-2025-53770, and CVE-2025-53771. These vulnerabilities apply to on-premises SharePoint Servers only. Customers should apply

    @msftsecresponse

    21 Jul 2025

    38237 Impressions

    44 Retweets

    101 Likes

    26 Bookmarks

    3 Replies

    8 Quotes

  29. CVE-2025-53771 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a… https://t.co/ntyEKRjF51

    @CVEnew

    20 Jul 2025

    556 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes