Loading HuntDB...

CVE-2025-53771

MEDIUM
Published 2025-07-20T22:16:52.203Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-53771. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
6.5
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
Not Available
Attack Complexity
Not Available
Privileges Required
Not Available
User Interaction
Not Available
Scope
Not Available

Impact Metrics

Confidentiality
Not Available
Integrity
Not Available
Availability
Not Available

Description

No description available

Available Exploits

No exploits available for this CVE.

Related News

Analyzing Sharepoint Exploits (CVE-2025-53770, CVE-2025-53771), (Wed, Jul 23rd)

A few days after the exploit originally became widely known, there are now many different SharePoint exploit attempts in circulation. We do see some scans by researchers to identify vulnerable systems (or to scan for common artifacts of compromise), and a few…

Sans.edu 2025-07-23 19:36
Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770

Microsoft disclosed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, that are exploited to attack SharePoint servers. Possession of these cryptographic machine keys allows an attacker to forge authentication tokens and maintain access even if …

Cloudflare.com 2025-07-22 16:30
Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)

CVE-2025-53770 and CVE-2025-53771 are vulnerabilities in on-premise Microsoft SharePoint Servers that evolved from previously patched flaws, allowing unauthenticated remote code execution through advanced deserialization and ViewState abuse.

Trendmicro.com 2025-07-21 23:08
ToolShell: Details of CVEs Affecting SharePoint Servers

Cisco Talos is aware of the ongoing exploitation of CVE-2025-53770 and CVE-2025-53771 in the wild. These are path traversal vulnerabilities affecting SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Server 2019.

Talosintelligence.com 2025-07-21 20:33
Microsoft Releases Emergency Patches for Actively Exploited SharePoint Zero-Days

Microsoft has released emergency security updates for two actively exploited zero-day vulnerabilities in SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, that have compromised servers worldwide in what researchers call "ToolShell" attacks. The U.S. C…

Slashdot.org 2025-07-21 15:23

Affected Products

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

Not EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Affected Products (ENISA)

microsoft
microsoft sharepoint enterprise server 2016

ENISA Scoring

CVSS Score (3.1)

6.5
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C

EPSS Score

0.070
probability

Data provided by ENISA EU Vulnerability Database. Last updated: July 24, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed MODERATE

GHSA-6pmq-337c-gv96

Advisory Details

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: July 21, 2025, Modified: July 21, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

13 posts
Reddit 5 hours, 47 minutes ago
Queasy-Frosting-5887
Exploit

SharePoint “ToolShell” zero day If SharePoint “ToolShell” zero day is ruining your day, we've got you covered. CVE-2025-53770 and CVE-2025-53771 don't have to get in the way of your detection and hunting activities.

Also mentions: CVE-2025-53770
5
5.0
View Original High Risk
Reddit 10 hours, 28 minutes ago
_cybersecurity_
Exploit

Serious Security Flaw: Metasploit Module Targets Active SharePoint Exploits **New Metasploit module exposes critical zero-day vulnerabilities in Microsoft SharePoint Server, allowing unauthenticated remote code execution.** **Key Points:** - SharePoint vulnerabilities (CVE-2025-53770/53771) exploited through a simple HTTP request. - Unauthenticated remote code execution on SharePoint 2019 with SYSTEM privileges. - Immediate …

Also mentions: CVE-2025-53770
1
1
3.0
View Original High Risk
Reddit 14 hours, 51 minutes ago
Sunitha_Sundar_5980
Exploit

Critical Zero-Day in Microsoft SharePoint Enables Unauthenticated Remote Code Execution CVE-2025-53770 (CVSS 9.8) is a critical zero-day vulnerability affecting **on-premises Microsoft SharePoint Server**. It is a variant of CVE-2025-49704 and stems from unsafe deserialization of untrusted data, allowing **unauthenticated remote code execution** over the network. Attackers exploit this flaw to …

1
1.0
View Original High Risk
Reddit 18 hours, 4 minutes ago
crstux
Exploit

🔥 Top 10 Trending CVEs (24/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2024-4947](https://nvd.nist.gov/vuln/detail/CVE-2024-4947)** - 📝 Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security …

1
1.0
View Original High Risk
Reddit 1 day, 16 hours ago
Leonie-Lionheard
Exploit

Microsoft bleibt stabil - diesmal Sharepoint > CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks > CVE-2025-49704 – SharePoint Remote Code Execution CVE-2025-49706 – SharePoint Post-auth Remote Code Execution CVE-2025-53770 – SharePoint ToolShell Authentication Bypass and Remote Code Execution CVE-2025-53771 – SharePoint ToolShell Path Traversal

9
9.0
View Original High Risk
Reddit 1 day, 18 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (23/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-49113](https://nvd.nist.gov/vuln/detail/CVE-2025-49113)** - 📝 Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading …

2
2.0
View Original High Risk
Reddit 2 days, 18 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (22/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53816](https://nvd.nist.gov/vuln/detail/CVE-2025-53816)** - 📝 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in …

2
2.0
View Original High Risk
Reddit 3 days, 5 hours ago
_cybersecurity_
Exploit

Microsoft Moves Quickly to Patch ToolShell Exploits Targeting SharePoint Servers **Microsoft has begun releasing critical updates to address zero-days that hackers exploited to compromise SharePoint servers.** **Key Points:** - Two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 were actively exploited against SharePoint Servers. - Attacks involved planting webshells and exfiltrating …

Also mentions: CVE-2025-53770
1
1
3.0
View Original High Risk
Reddit 3 days, 5 hours ago
Poutcheki

Proactive Security for CVE-2025-53770 and CVE-2025-53771 SharePoint Attacks

Also mentions: CVE-2025-53770
Reddit 3 days, 10 hours ago
fluffy_warthog10

On-Prem Sharepoint servers compromised [https://research.eye.security/sharepoint-under-siege/](https://research.eye.security/sharepoint-under-siege/) CVE Update Guide: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53771](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53771) What to do: [https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/](https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/) (I was supposed to be off today)

Also mentions: CVE-2025-53770
79
30
139.0

References

Published: 2025-07-20T22:16:52.203Z
Last Modified: 2025-07-23T16:22:55.361Z
Copied to clipboard!