Microsoft SharePoint Server是美国微软(Microsoft)公司的一款协作平台。 Microsoft SharePoint Server存在安全漏洞,该漏洞源于反序列化不受信任数据,可能导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | 16.0.0< 16.0.5513.1001 |
affected |
| Microsoft | Microsoft SharePoint Server 2019 | 16.0.0< 16.0.10417.20037 |
affected |
| Microsoft | Microsoft SharePoint Server Subscription Edition | 16.0.0< 16.0.18526.20508 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | 16.0.0 ~ 16.0.5513.1001 | - |
|
| Microsoft | Microsoft SharePoint Server 2019 | 16.0.0 ~ 16.0.10417.20037 | - |
|
| Microsoft | Microsoft SharePoint Server Subscription Edition | 16.0.0 ~ 16.0.18526.20508 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53770.yaml | POC Details |
| 2 | Detects a persistent webshell named 'spinstall0.aspx' deployed on Microsoft SharePoint servers. This file exposes sensitive cryptographic machineKey values from the SharePoint configuration, indicating the presence of a ToolShell backdoor implant. This implant is linked to targeted post-auth RCE campaigns exploiting CVE-2025-53770. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/backdoor/sharepoint-toolshell-backdoor.yaml | POC Details |
| 3 | CVE-2025-53770 | https://github.com/B1ack4sh/Blackash-CVE-2025-53770 | POC Details |
| 4 | A critical zero-day vulnerability CVE‑2025‑53770 has been actively exploited in the wild against on-premises Microsoft SharePoint Server. Dubbed "ToolShell," this exploit leverages a deserialization flaw (variant of CVE‑2025‑49706, CVSS: 6.3). | https://github.com/RukshanaAlikhan/CVE-2025-53770 | POC Details |
| 5 | None | https://github.com/Bluefire-Redteam-Cybersecurity/bluefire-sharepoint-cve-2025-53770 | POC Details |
| 6 | This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by @n1chr0x and @BlackRazer67 | https://github.com/n1chr0x/ZeroPoint | POC Details |
| 7 | POC | https://github.com/kaizensecurity/CVE-2025-53770 | POC Details |
| 8 | A comprehensive security monitoring solution for SharePoint Server with specific protection against CVE-2025-53770 and other threats | https://github.com/paolokappa/SharePointSecurityMonitor | POC Details |
| 9 | SharePoint WebPart Injection Exploit Tool | https://github.com/soltanali0/CVE-2025-53770-Exploit | POC Details |
| 10 | Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability. | https://github.com/hazcod/CVE-2025-53770 | POC Details |
| 11 | ToolShell scanner - CVE-2025-53770 and detection information | https://github.com/ZephrFish/CVE-2025-53770-Scanner | POC Details |
| 12 | Hunting for Critical SharePoint Vulnerability CVE-2025-53770 | https://github.com/siag-itsec/CVE-2025-53770-Hunting | POC Details |
| 13 | Comprueba si un servidor SharePoint on-premises es vulnerable a CVE-2025-53770 | https://github.com/grupooruss/CVE-2025-53770-Checker | POC Details |
| 14 | None | https://github.com/tripoloski1337/CVE-2025-53770-scanner | POC Details |
| 15 | A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706. | https://github.com/AdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE | POC Details |
| 16 | CVE-2025-53770 – Vulnerability Research & Exploitation | https://github.com/b33b0y/CVE-2025-53770 | POC Details |
| 17 | None | https://github.com/GreenForceNetwork/Toolshell_CVE-2025-53770 | POC Details |
| 18 | None | https://github.com/imbas007/CVE-2025-53770-Vulnerable-Scanner | POC Details |
| 19 | A Python-based reconnaissance scanner for safely identifying potential exposure to SharePoint vulnerability CVE-2025-53770. | https://github.com/Sec-Dan/CVE-2025-53770-Scanner | POC Details |
| 20 | Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770) | https://github.com/MuhammadWaseem29/CVE-2025-53770 | POC Details |
| 21 | Exploit tool for SharePoint WebPart Injection via ToolPane.aspx, enabling .NET deserialization and remote code execution. 🛠️🔍 Secure your SharePoint now! | https://github.com/bijikutu/CVE-2025-53770-Exploit | POC Details |
| 22 | Explore the Microsoft SharePoint CVE-2025-53770 proof of concept. Learn about this vulnerability and its implications. 🐙💻 | https://github.com/Lapesha/CVE-2025-53770 | POC Details |
| 23 | Scanner for CVE-2025-53770, a SharePoint vulnerability. Check if your server is vulnerable and extract version info. 🛠️🔍 | https://github.com/Hassanopop/CVE-2025-53770 | POC Details |
| 24 | Identify exposure to the critical SharePoint vulnerability CVE-2025-53770 with this effective scanner tool. Secure your systems today! 🛡️🔍 | https://github.com/m4r1x/CVE-2025-53770-Scanner | POC Details |
| 25 | Exploit & research for CVE‑2025‑53770 – a zero‑day remote code execution vulnerability in Microsoft SharePoint (on‑premises). | https://github.com/Kamal-Hegazi/CVE-2025-53770-SharePoint-RCE | POC Details |
| 26 | A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition) | https://github.com/exfil0/CVE-2025-53770 | POC Details |
| 27 | Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771 | https://github.com/zach115th/ToolShellFinder | POC Details |
| 28 | Detection rules for CVE-2025-53770 | https://github.com/nisargsuthar/suricata-rule-CVE-2025-53770 | POC Details |
| 29 | None | https://github.com/bharath-cyber-root/sharepoint-toolshell-cve-2025-53770 | POC Details |
| 30 | Do you really think SharePoint is safe? | https://github.com/Rabbitbong/OurSharePoint-CVE-2025-53770 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet