cbcvebase.
CVE-2025-53770
published 2025-07-20

CVE-2025-53770: Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2025-07-21
Exploited in the wild
EPSS
99.98%
100.0th percentile
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5513.100116.0.5513.1001
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2003716.0.10417.20037
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.18526.2050816.0.18526.20508
microsoftsharepoint_server< 16.0.18526.2050816.0.18526.20508
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition

Detection & IOCsextracted from sources · hover to see the quote

ip134.199.202[.]205
ip104.238.159[.]149
ip188.130.206[.]168
ip131.226.2[.]6
ip107.191.58[.]76
ip96.9.125[.]147
ip103.186.30[.]186
filenameSpinstall0.aspx
urlc34718cbb4c6.ngrok-free[.]app/file.ps1
hash92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514
pathC:\PROGRA~1\COMMON~1\MICROS~1\WEBSER~1\16\TEMPLATE\LAYOUTS\spinstall0.aspx
pathC:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\
url/_layouts/15/ToolPane.aspx?DisplayMode=Edit
url/_layouts/15/spinstall0.aspx
processw3wp.exe spawning encoded PowerShell
  • Monitor for POST requests to /_layouts/15/ToolPane.aspx?DisplayMode=Edit with a Referer header of /_layouts/SignOut.aspx — this is the authentication bypass step of the ToolShell chain (CVE-2025-53771).
  • Alert on creation of any .aspx files (especially spinstall0.aspx) in the SharePoint LAYOUTS directory: C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\
  • Detect w3wp.exe spawning encoded PowerShell child processes — a strong indicator of post-exploitation activity on a compromised SharePoint server.
  • Active exploitation was first observed July 18, 2025; nearly all incident response engagements began within 10 days. Prioritize hunting on SharePoint servers exposed to the internet during this window.
  • A PoC exploit for CVE-2025-53770 was published on GitHub after patches were released, significantly lowering the barrier for additional threat actors. Treat any unpatched internet-facing SharePoint server as likely compromised.
  • ·CVE-2025-53770 and CVE-2025-53771 are bypasses of previously patched flaws (CVE-2025-49704 and CVE-2025-49706 respectively); servers that applied July 2025 Patch Tuesday updates are still vulnerable and require the emergency patches.
  • ·SharePoint Online (Microsoft 365) is NOT affected; only on-premises SharePoint Server deployments are vulnerable, including self-managed instances hosted in cloud environments (Azure, AWS, GCP).
  • ·SharePoint Server 2010 and 2013 are end-of-life and will not receive patches; they are confirmed affected and should be isolated or upgraded.
  • ·In many reported cases it is unclear whether observed in-the-wild exploitation reflects abuse of the original CVEs (CVE-2025-49704/49706) or their bypasses (CVE-2025-53770/53771); IOCs may overlap across both exploit generations.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.