Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2025-53771 — Improper Authentication in Microsoft Sharepoint Enterprise Server 2016
Severity
6.5MEDIUMNVD
CISA8.8
EPSS
39.6%
top 2.68%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 20
Latest updateDec 3
Description
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5
Affected Packages4 packages
🔴Vulnerability Details
3GHSA▶
GHSA-6pmq-337c-gv96: Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform↗2025-07-21
💥Exploits & PoCs
3Nuclei▶
Microsoft SharePoint Server - Authentication Bypass (ToolShell)
Metasploit▶
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)↗
Nuclei▶
Microsoft SharePoint Server - Remote Code Execution (ToolShell)
🔍Detection Rules
1📋Vendor Advisories
2🕵️Threat Intelligence
23Unit42▶
Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated August 12)↗2025-07-31