目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-53770 PoC — Microsoft SharePoint Server 安全漏洞

来源
关联漏洞
标题: Microsoft SharePoint Server 安全漏洞 (CVE-2025-53770)
Description:Microsoft SharePoint Server是美国微软(Microsoft)公司的一款协作平台。 Microsoft SharePoint Server存在安全漏洞,该漏洞源于反序列化不受信任数据,可能导致远程代码执行。
Description
This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint.  Created by @n1chr0x and @BlackRazer67
介绍
# ZeroPoint.ps1

> ⚠ A defensive PowerShell utility to detect and mitigate exploitation of the *CVE-2025-53770* zero-day vulnerability in *Microsoft SharePoint Server*.

![Script Execution Screenshot](Zeropoint.png)
---

## 🔍 What it Does

This PowerShell script is designed to:

- Detect compromise indicators, such as suspicious .aspx webshells
- Parse ULS logs to identify deserialization/spoofing activity
- Verify critical security settings like AMSI and Microsoft Defender
- Provide *optional emergency mitigation* to disconnect external interfaces

---

## 🚨 CVE Details

- *CVE:* CVE-2025-53770  
- *Type:* Remote Code Execution (RCE)  
- *CVSS Score:* 9.8 (Critical)  
- *Affected:* Microsoft SharePoint Server (on-premises)  
- *Status:* Zero-day *actively exploited*, no official patch at time of script release  

---

## 👨‍💻 Authors

- @n1chr0x
- @BlackRazer67

---

## 🧰 Usage

### 🔸 Run the script on your SharePoint server:

1. Open *PowerShell as Administrator*
2. Navigate to the script directory.
3. Run "powershell -ep bypass"
4. Run the script ".\ZeroPoint.ps1"

## ✨ Features

- Clean CLI output
- Easily auditable
- Safe for production — does *not* exploit or modify SharePoint
- Compatible with:
  - Windows Server 2016+
  - SharePoint Server 2016 / 2019 / Subscription Edition
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →