SharePoint ToolShell RCE Zero-Day
- شناسه CVE: CVE-2025-53770
- شدت: بحرانی
- امتیاز CVSS: 9.8
- فروشنده/سازنده: Microsoft
RCESharePointZero-DayToolShellCritical
ToolShell is a critical zero-day RCE vulnerability in Microsoft SharePoint Server that has been actively exploited in worldwide attacks. It is typically chained with CVE-2025-53771 (Header Spoofing) for a complete unauthenticated attack.
## Vulnerability Overview
An unsafe deserialization vulnerability in the SharePoint Server API allows unauthenticated remote code execution. The vulnerability exists in the server's handling of serialized ViewState data, where a crafted .NET deserialization payload can trigger arbitrary code execution with the privileges of the SharePoint application pool (typically IIS APPPOOL identity).
## Technical Details
- **Type:** Unsafe Deserialization → RCE (CWE-502)
- **Root Cause:** SharePoint's API endpoint processes ViewState data using BinaryFormatter without proper MAC validation when combined with the header spoofing vulnerability (CVE-2025-53771). This allows injection of arbitrary .NET gadget chains.
- **Attack Chain:** CVE-2025-53771 bypasses authentication → CVE-2025-53770 achieves code execution
- **No Authentication Required** (when chained)
## Global Exploitation
- Mass scanning and exploitation campaigns detected worldwide since January 2025.
- Government agencies, educational institutions, and enterprises targeted.
- Webshells deployed for persistent access.
- Data exfiltration observed in multiple incidents.
## Affected Versions
- SharePoint Server 2019 (all builds before February 2025 patch)
- SharePoint Server Subscription Edition (before KB5002723)
## Vulnerability Overview
An unsafe deserialization vulnerability in the SharePoint Server API allows unauthenticated remote code execution. The vulnerability exists in the server's handling of serialized ViewState data, where a crafted .NET deserialization payload can trigger arbitrary code execution with the privileges of the SharePoint application pool (typically IIS APPPOOL identity).
## Technical Details
- **Type:** Unsafe Deserialization → RCE (CWE-502)
- **Root Cause:** SharePoint's API endpoint processes ViewState data using BinaryFormatter without proper MAC validation when combined with the header spoofing vulnerability (CVE-2025-53771). This allows injection of arbitrary .NET gadget chains.
- **Attack Chain:** CVE-2025-53771 bypasses authentication → CVE-2025-53770 achieves code execution
- **No Authentication Required** (when chained)
## Global Exploitation
- Mass scanning and exploitation campaigns detected worldwide since January 2025.
- Government agencies, educational institutions, and enterprises targeted.
- Webshells deployed for persistent access.
- Data exfiltration observed in multiple incidents.
## Affected Versions
- SharePoint Server 2019 (all builds before February 2025 patch)
- SharePoint Server Subscription Edition (before KB5002723)
نرمافزارهای تحت تأثیر
- Microsoft SharePoint Server 2019
- SharePoint Server Subscription Edition