VulnCity

SharePoint ToolShell RCE Zero-Day

  • شناسه CVE: CVE-2025-53770
  • شدت: بحرانی
  • امتیاز CVSS: 9.8
  • فروشنده/سازنده: Microsoft
RCESharePointZero-DayToolShellCritical
ToolShell is a critical zero-day RCE vulnerability in Microsoft SharePoint Server that has been actively exploited in worldwide attacks. It is typically chained with CVE-2025-53771 (Header Spoofing) for a complete unauthenticated attack.

## Vulnerability Overview
An unsafe deserialization vulnerability in the SharePoint Server API allows unauthenticated remote code execution. The vulnerability exists in the server's handling of serialized ViewState data, where a crafted .NET deserialization payload can trigger arbitrary code execution with the privileges of the SharePoint application pool (typically IIS APPPOOL identity).

## Technical Details
- **Type:** Unsafe Deserialization → RCE (CWE-502)
- **Root Cause:** SharePoint's API endpoint processes ViewState data using BinaryFormatter without proper MAC validation when combined with the header spoofing vulnerability (CVE-2025-53771). This allows injection of arbitrary .NET gadget chains.
- **Attack Chain:** CVE-2025-53771 bypasses authentication → CVE-2025-53770 achieves code execution
- **No Authentication Required** (when chained)

## Global Exploitation
- Mass scanning and exploitation campaigns detected worldwide since January 2025.
- Government agencies, educational institutions, and enterprises targeted.
- Webshells deployed for persistent access.
- Data exfiltration observed in multiple incidents.

## Affected Versions
- SharePoint Server 2019 (all builds before February 2025 patch)
- SharePoint Server Subscription Edition (before KB5002723)

نرم‌افزارهای تحت تأثیر

  • Microsoft SharePoint Server 2019
  • SharePoint Server Subscription Edition