Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE — A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706. | Kitploit
Tools/GitHubGitHub/adityabhatt3010/cve-2025-53770-sharepoint-zero-day-variant-exploited-for-full-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingIncident Response
GitHubadityabhatt3010/cve-2025-53770-sharepoint-zero-day-variant-exploited-for-full-rce

CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE

A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.

View Repository
1171 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE‑2025‑53770 – SharePoint Zero-Day Variant Exploited for Full RCE

A Critical Escalation from CVE‑2025‑49706
By Aditya Bhatt – Red Team | VAPT


📌 TL;DR

CVE‑2025‑53770 is a critical (CVSS 9.8) zero-auth RCE vulnerability in Microsoft SharePoint now actively exploited in the wild. This isn’t a standalone issue—it’s a variant of CVE‑2025‑49706, which I previously covered. But while CVE‑2025‑49706 required authentication, 53770 doesn’t.

This is unauthenticated code execution, with real-world web shell drops and privilege escalation in active attacks. Patch now.


🔁 In Case You Missed It:

I previously analyzed CVE‑2025‑49706 – a spoofing vulnerability in SharePoint that allowed token manipulation, web shell uploads, and lateral movement from an authenticated foothold.

CVE‑2025‑53770 builds on the same foundation but skips the login altogether.


🧠 What is CVE‑2025‑53770?

  • Type: Unauthenticated Remote Code Execution (RCE)

  • Severity: CVSS 9.8 (Critical)

  • Affected Products:

    • SharePoint Server 2016 (unpatched)
    • SharePoint Server 2019
    • SharePoint Server Subscription Edition

design-a-high-impact-cybersecurity-artic_CdRES1GBSdam1Yc_c8SpnQ_jqOqJQAeRhiHAaQQn1Us9g


🔍 Root Cause

According to Microsoft, this is a variant of CVE‑2025‑49706 and involves improper handling of crafted authentication tokens—combined with malicious __VIEWSTATE payloads—that lead to direct execution in IIS worker processes.


⚔️ Real-World Attacks

🚨 ToolShell Campaign Update:

  • Attackers are chaining:

    • CVE‑2025‑49704 (deserialization bug)
    • CVE‑2025‑49706 (spoofed header + auth bypass)
    • CVE‑2025‑53770 (unauth RCE)
  • Dropping:

    • spinstall0.aspx web shell
    • Payloads like SuspSignoutReq.exe
    • Persistence tools under w3wp.exe

🎯 Affected Targets (based on MSRC reports):

  • Government and Education sectors
  • On-prem SharePoint portals
  • Any SharePoint instance exposed to the internet without July patches

🧪 Attack Flow (Simplified):

  1. 📥 Malicious request sent to vulnerable endpoint (unauthenticated)
  2. 🧾 Injected __VIEWSTATE payload or forged token bypasses validation
  3. 💣 Code executed inside IIS (w3wp.exe) under NT AUTHORITY\SYSTEM
  4. 🐚 Web shell uploaded, remote access established
  5. 🛰️ C2 communication initiated, lateral movement begins

_- visual selection


🛡️ Mitigation & Patching

✅ Patch Immediately

Microsoft released out-of-band security updates on July 20–21, 2025:

  • SharePoint 2019 ➝ KB5002741
  • SharePoint SE ➝ KB5002755
  • SharePoint 2016 is pending — isolate servers ASAP

🔗 Microsoft Patch Catalog


✅ Harden Systems

  • Disable external access to SharePoint until patched
  • Rotate machine keys / viewstate validation keys
  • Enable AMSI + Defender AV with these PowerShell flags:
Set-MpPreference -EnableControlledFolderAccess Enabled
Set-MpPreference -EnableScriptScanning $true

🔎 Detection & Threat Hunting

IOC Examples:

  • spinstall0.aspx

  • SuspSignoutReq.exe

  • Large encoded __VIEWSTATE in POST payloads

  • Suspicious process tree:

    • w3wp.exe → cmd.exe → powershell.exe

Defender KQL Hunt:

DeviceFileEvents
| where FileName contains "spinstall0.aspx" or FolderPath contains "inetpub"
| where ActionType == "FileCreated"

🔗 Connection to CVE‑2025‑49706

CVE IDAccess RequiredImpactExploitation
CVE‑2025‑49706AuthenticatedSpoofing / Shell DropConfirmed
CVE‑2025‑53770UnauthenticatedRCE + SYSTEM PrivilegeActive

Microsoft confirmed 53770 as a variant of 49706, now weaponized into unauthenticated RCE.


🧠 Final Thoughts

This isn't just another CVE drop. CVE‑2025‑53770 is one of the most dangerous SharePoint vulnerabilities in recent memory. It builds on an already-bad spoofing flaw (49706) and eliminates the only barrier—authentication.

If you're running an on-prem SharePoint instance and haven't patched since early July 2025, assume compromise and hunt aggressively.

a-high-impact-cybersecurity-article-cove_GJ-Xd9NwTO2PWPeOiTkJKg_jqOqJQAeRhiHAaQQn1Us9g


📚 References

  • Microsoft Blog – CVE-2025-53770
  • SecurityWeek Coverage
  • My CVE‑2025‑49706 Analysis
  • Wiz Threat Intel

👨‍💻 About the Author

I'm a cybersecurity practitioner focused on offensive security, exploit analysis, and red team operations. I’ve ranked in the top 2% on TryHackMe and published security tools like KeySentry, ShadowHash, and PixelPhantomX. I hold certifications like CEH, Security+, and the IIT Kanpur Red Team Certificate, and write regularly for InfoSec WriteUps and other security platforms.

🔗 GitHub: @AdityaBhatt3010
✍️ Medium: @adityabhatt3010
💼 LinkedIn: Aditya Bhatt


Download Tool