CVE-2025-53771

MEDIUM EXPLOITED RANSOMWARE NUCLEI

Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2025-53771 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including Viettel Cyber Security, sfewer-r7, including a Metasploit module exploits/windows/http/sharepoint_toolpane_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits CVE-2025-53771, an authentication bypass vulnerability in Microsoft SharePoint Server, combined with unsafe deserialization (CVE-2025-49704) to achieve unauthenticated remote code execution. It uses a crafted gadget chain involving DataSet and LosFormatter to execute arbitrary commands.

Description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Viettel Cyber Security, sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sharepoint_toolpane_rce.rb

This Metasploit module exploits CVE-2025-53771, an authentication bypass vulnerability in Microsoft SharePoint Server, combined with unsafe deserialization (CVE-2025-49704) to achieve unauthenticated remote code execution. It uses a crafted gadget chain involving DataSet and LosFormatter to execute arbitrary commands.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft SharePoint Server (various versions including 2019, 2016, and Subscription Edition)
No auth needed
Prerequisites: Network access to the SharePoint server · Vulnerable SharePoint version
devstral-2 · analyzed Jun 05, 2026 Full analysis →

Nuclei Templates (1)

Microsoft SharePoint Server - Authentication Bypass (ToolShell)
MEDIUMVERIFIEDby _l0gg,SamIntruder,sfewer-r7,iamnoooob,pdresearch
Shodan: http.component:"sharepoint"

Scores

CVSS v3 6.5
EPSS 0.9989
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2025-07-18
Ransomware Use Confirmed
CWE
CWE-287
Status published
Products (3)
microsoft/sharepoint_server 2016
microsoft/sharepoint_server 2019
microsoft/sharepoint_server < 16.0.18526.20508
Published Jul 20, 2025
Tracked Since Feb 18, 2026