CVE-2025-53770

CRITICAL KEV RANSOMWARE NUCLEI

Microsoft SharePoint Server - Code Injection

Title source: llm

Description

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

Exploits (52)

exploitdb WORKING POC
by Agampreet Singh · pythonremotewindows
https://www.exploit-db.com/exploits/52405
nomisec WORKING POC 311 stars
by soltanali0 · remote
https://github.com/soltanali0/CVE-2025-53770-Exploit
nomisec WORKING POC 55 stars
by MuhammadWaseem29 · remote
https://github.com/MuhammadWaseem29/CVE-2025-53770
nomisec SCANNER 44 stars
by hazcod · remote
https://github.com/hazcod/CVE-2025-53770
nomisec SUSPICIOUS 43 stars
by kaizensecurity · remote
https://github.com/kaizensecurity/CVE-2025-53770
nomisec SCANNER 18 stars
by ZephrFish · poc
https://github.com/ZephrFish/CVE-2025-53770-Scanner
nomisec SCANNER 14 stars
by 3a7 · remote
https://github.com/3a7/CVE-2025-53770
nomisec WRITEUP 8 stars
by AdityaBhatt3010 · poc
https://github.com/AdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE
nomisec WORKING POC 4 stars
by saladin0x1 · remote
https://github.com/saladin0x1/CVE-2025-53770
nomisec WORKING POC 4 stars
by Immersive-Labs-Sec · remote
https://github.com/Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
nomisec WORKING POC 4 stars
by exfil0 · remote
https://github.com/exfil0/CVE-2025-53770
nomisec SCANNER 3 stars
by Bluefire-Redteam-Cybersecurity · poc
https://github.com/Bluefire-Redteam-Cybersecurity/bluefire-sharepoint-cve-2025-53770
nomisec WORKING POC 2 stars
by Rabbitbong · remote
https://github.com/Rabbitbong/OurSharePoint-CVE-2025-53770
nomisec SCANNER 2 stars
by Sec-Dan · poc
https://github.com/Sec-Dan/CVE-2025-53770-Scanner
nomisec WRITEUP 1 stars
by anwakub · poc
https://github.com/anwakub/CVE-2025-53770
nomisec WRITEUP 1 stars
by Cameloo1 · poc
https://github.com/Cameloo1/sharepoint-toolshell-micro-postmortem
nomisec WRITEUP 1 stars
by paolokappa · poc
https://github.com/paolokappa/SharePointSecurityMonitor
nomisec SCANNER 1 stars
by imbas007 · poc
https://github.com/imbas007/CVE-2025-53770-Vulnerable-Scanner
nomisec SCANNER 1 stars
by tripoloski1337 · poc
https://github.com/tripoloski1337/CVE-2025-53770-scanner
nomisec WRITEUP
by Zedocun · poc
https://github.com/Zedocun/SharePoint-ToolShell-CVE-2025-53770-Incident-Analysis
nomisec SCANNER
by rbctee · remote
https://github.com/rbctee/CVE-2025-53770
nomisec SCANNER
by zach115th · poc
https://github.com/zach115th/ToolShellFinder
nomisec WRITEUP
by victormbogu1 · poc
https://github.com/victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
nomisec WRITEUP
by Michaael01 · poc
https://github.com/Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell
nomisec SCANNER
by daryllundy · poc
https://github.com/daryllundy/CVE-2025-53770
nomisec WORKING POC
by go-bi · remote
https://github.com/go-bi/sharepoint-CVE-2025-53770
nomisec WORKING POC
by ghostn4444 · remote
https://github.com/ghostn4444/CVE-2025-53770
nomisec WRITEUP
by CyprianAtsyor · poc
https://github.com/CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
github SCANNER
by behnamvanda · shellinfoleak
https://github.com/behnamvanda/CVE-2025-53770-Checker
nomisec WORKING POC
by Agampreet-Singh · infoleak
https://github.com/Agampreet-Singh/CVE-2025-53770
nomisec WORKING POC
by harryhaxor · remote
https://github.com/harryhaxor/CVE-2025-53770-SharePoint-Deserialization-RCE-PoC
nomisec SCANNER
by bitsalv · poc
https://github.com/bitsalv/ToolShell-Honeypot
nomisec SCANNER
by 0x-crypt · remote
https://github.com/0x-crypt/CVE-2025-53770-Scanner
nomisec WORKING POC
by r3xbugbounty · remote
https://github.com/r3xbugbounty/CVE-2025-53770
nomisec WRITEUP
by bossnick98 · poc
https://github.com/bossnick98/-SOC342---CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-and-RCE
nomisec WORKING POC
by BirdsAreFlyingCameras · remote
https://github.com/BirdsAreFlyingCameras/CVE-2025-53770_Raw-HTTP-Request-Generator
nomisec WORKING POC
by Udyz · remote
https://github.com/Udyz/CVE-2025-53770-Exploit
nomisec SCANNER
by nisargsuthar · poc
https://github.com/nisargsuthar/suricata-rule-CVE-2025-53770
nomisec WRITEUP
by bharath-cyber-root · poc
https://github.com/bharath-cyber-root/sharepoint-toolshell-cve-2025-53770
nomisec WORKING POC
by 0xray5c68616e37 · remote
https://github.com/0xray5c68616e37/cve-2025-53770
nomisec WORKING POC
by GreenForceNetworks · poc
https://github.com/GreenForceNetworks/Toolshell_CVE-2025-53770
nomisec SCANNER
by grupooruss · poc
https://github.com/grupooruss/CVE-2025-53770-Checker
nomisec SCANNER
by gmh5225 · poc
https://github.com/gmh5225/ZeroPoint
nomisec SCANNER
by n1chr0x · poc
https://github.com/n1chr0x/ZeroPoint
nomisec NO CODE
by RukshanaAlikhan · poc
https://github.com/RukshanaAlikhan/CVE-2025-53770
nomisec WRITEUP
by yosasasutsut · poc
https://github.com/yosasasutsut/Blackash-CVE-2025-53770
patchapalooza WORKING POC
by GreenForceNetwork · remote
https://github.com/GreenForceNetwork/Toolshell_CVE-2025-53770

Nuclei Templates (1)

Microsoft SharePoint Server - Remote Code Execution (ToolShell)
CRITICALVERIFIEDby _l0gg,SamIntruder,sfewer-r7,iamnoooob,pdresearch
Shodan: http.component:"sharepoint"

References (13)

Scores

CVSS v3 9.8
EPSS 0.9036
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-07-20
VulnCheck KEV 2025-07-18
ENISA EUVD EUVD-2025-23309
Ransomware Use Confirmed
CWE
CWE-502
Status published
Products (3)
microsoft/sharepoint_server 2016
microsoft/sharepoint_server 2019
microsoft/sharepoint_server < 16.0.18526.20508
Published Jul 20, 2025
KEV Added Jul 20, 2025
Tracked Since Feb 18, 2026