Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-53771Improper Authentication in Microsoft Sharepoint Enterprise Server 2016

Severity
6.5MEDIUMNVD
CISA8.8
EPSS
39.6%
top 2.68%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 20
Latest updateDec 3

Description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages4 packages

NVDmicrosoft/sharepoint_server< 16.0.18526.20508+2
CVEListV5microsoft/microsoft_sharepoint_server_201916.0.016.0.10417.20037
CVEListV5microsoft/microsoft_sharepoint_enterprise_server_201616.0.016.0.5513.1001
CVEListV5microsoft/microsoft_sharepoint_server_subscription_edition16.0.016.0.18526.20508

🔴Vulnerability Details

3
GHSA
GHSA-6pmq-337c-gv96: Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform2025-07-21
CVEList
Microsoft SharePoint Server Spoofing Vulnerability2025-07-20
VulnCheck
Microsoft SharePoint Improper Authentication2025

💥Exploits & PoCs

3
Nuclei
Microsoft SharePoint Server - Authentication Bypass (ToolShell)
Metasploit
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Nuclei
Microsoft SharePoint Server - Remote Code Execution (ToolShell)

🔍Detection Rules

1
Elastic
Potential Toolshell Initial Exploit (CVE-2025-53770 & CVE-2025-53771)

📋Vendor Advisories

2
CISA
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability2025-07-20
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability2025-07-08

🕵️Threat Intelligence

23
Securelist
Exploits and vulnerabilities in Q3 20252025-12-03
Unit42
Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks2025-08-05
Unit42
Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated August 12)2025-07-31
Securelist
ToolShell: a story of five vulnerabilities in Microsoft SharePoint2025-07-25
Securelist
ToolShell: a story of five vulnerabilities in Microsoft SharePoint2025-07-25

📐Framework References

1
ATT&CK
SharePoint ToolShell Exploitation
CVE-2025-53771 — Improper Authentication in Microsoft | cvebase