CVE-2025-53771
MEDIUM EXPLOITED RANSOMWARE NUCLEIMicrosoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Title source: metasploitExploitation Summary
CVE-2025-53771 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.
EIP tracks 1 public exploit from researchers including Viettel Cyber Security, sfewer-r7, including a Metasploit module exploits/windows/http/sharepoint_toolpane_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits CVE-2025-53771, an authentication bypass vulnerability in Microsoft SharePoint Server, combined with unsafe deserialization (CVE-2025-49704) to achieve unauthenticated remote code execution. It uses a crafted gadget chain involving DataSet and LosFormatter to execute arbitrary commands.
Description
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Exploits (1)
This Metasploit module exploits CVE-2025-53771, an authentication bypass vulnerability in Microsoft SharePoint Server, combined with unsafe deserialization (CVE-2025-49704) to achieve unauthenticated remote code execution. It uses a crafted gadget chain involving DataSet and LosFormatter to execute arbitrary commands.
Nuclei Templates (1)
http.component:"sharepoint"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N