Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE — A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706. | Kitploit
Tools/GitHubGitHub/adityabhatt3010/cve-2025-53770-sharepoint-zero-day-variant-exploited-for-full-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingIncident Response
GitHubadityabhatt3010/cve-2025-53770-sharepoint-zero-day-variant-exploited-for-full-rce

CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE

A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.

View Repository
1111 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE‑2025‑53770 – SharePoint Zero-Day Variant Exploited for Full RCE

A Critical Escalation from CVE‑2025‑49706
By Aditya Bhatt – Red Team | VAPT


📌 TL;DR

CVE‑2025‑53770 is a critical (CVSS 9.8) zero-auth RCE vulnerability in Microsoft SharePoint now actively exploited in the wild. This isn’t a standalone issue—it’s a variant of CVE‑2025‑49706, which I previously covered. But while CVE‑2025‑49706 required authentication, 53770 doesn’t.

This is unauthenticated code execution, with real-world web shell drops and privilege escalation in active attacks. Patch now.


🔁 In Case You Missed It:

I previously analyzed CVE‑2025‑49706 – a spoofing vulnerability in SharePoint that allowed token manipulation, web shell uploads, and lateral movement from an authenticated foothold.

CVE‑2025‑53770 builds on the same foundation but skips the login altogether.


🧠 What is CVE‑2025‑53770?

  • Type: Unauthenticated Remote Code Execution (RCE)

  • Severity: CVSS 9.8 (Critical)

  • Affected Products:

    • SharePoint Server 2016 (unpatched)
    • SharePoint Server 2019
    • SharePoint Server Subscription Edition
  • design-a-high-impact-cybersecurity-artic_CdRES1GBSdam1Yc_c8SpnQ_jqOqJQAeRhiHAaQQn1Us9g


    🔍 Root Cause

    According to Microsoft, this is a variant of CVE‑2025‑49706 and involves improper handling of crafted authentication tokens—combined with malicious __VIEWSTATE payloads—that lead to direct execution in IIS worker processes.


    ⚔️ Real-World Attacks

    🚨 ToolShell Campaign Update:

    • Attackers are chaining:

      • CVE‑2025‑49704 (deserialization bug)
      • CVE‑2025‑49706 (spoofed header + auth bypass)
      • CVE‑2025‑53770 (unauth RCE)
    • Dropping:

      • spinstall0.aspx web shell
      • Payloads like SuspSignoutReq.exe
      • Persistence tools under w3wp.exe

    🎯 Affected Targets (based on MSRC reports):

    • Government and Education sectors
    • On-prem SharePoint portals
    • Any SharePoint instance exposed to the internet without July patches

    🧪 Attack Flow (Simplified):

    1. 📥 Malicious request sent to vulnerable endpoint (unauthenticated)
    2. 🧾 Injected __VIEWSTATE payload or forged token bypasses validation
    3. 💣 Code executed inside IIS (w3wp.exe) under NT AUTHORITY\SYSTEM
    4. 🐚 Web shell uploaded, remote access established
    5. 🛰️ C2 communication initiated, lateral movement begins

    _- visual selection


    🛡️ Mitigation & Patching

    ✅ Patch Immediately

    Microsoft released out-of-band security updates on July 20–21, 2025:

    • SharePoint 2019 ➝ KB5002741
    • SharePoint SE ➝ KB5002755
    • SharePoint 2016 is pending — isolate servers ASAP

    🔗 Microsoft Patch Catalog


    ✅ Harden Systems

    • Disable external access to SharePoint until patched
    • Rotate machine keys / viewstate validation keys
    • Enable AMSI + Defender AV with these PowerShell flags:
    root@kitploit:~
    Set-MpPreference -EnableControlledFolderAccess Enabled
    Set-MpPreference -EnableScriptScanning $true
    

    🔎 Detection & Threat Hunting

    IOC Examples:

    • spinstall0.aspx

    • SuspSignoutReq.exe

    • Large encoded __VIEWSTATE in POST payloads

    • Suspicious process tree:

      • w3wp.exe → cmd.exe → powershell.exe

    Defender KQL Hunt:

    root@kitploit:~
    DeviceFileEvents
    | where FileName contains "spinstall0.aspx" or FolderPath contains "inetpub"
    | where ActionType == "FileCreated"
    

    🔗 Connection to CVE‑2025‑49706

    CVE IDAccess RequiredImpactExploitation
    CVE‑2025‑49706AuthenticatedSpoofing / Shell DropConfirmed
    CVE‑2025‑53770UnauthenticatedRCE + SYSTEM PrivilegeActive

    Microsoft confirmed 53770 as a variant of 49706, now weaponized into unauthenticated RCE.


    🧠 Final Thoughts

    This isn't just another CVE drop. CVE‑2025‑53770 is one of the most dangerous SharePoint vulnerabilities in recent memory. It builds on an already-bad spoofing flaw (49706) and eliminates the only barrier—authentication.

    If you're running an on-prem SharePoint instance and haven't patched since early July 2025, assume compromise and hunt aggressively.

    a-high-impact-cybersecurity-article-cove_GJ-Xd9NwTO2PWPeOiTkJKg_jqOqJQAeRhiHAaQQn1Us9g


    📚 References

    • Microsoft Blog – CVE-2025-53770
    • SecurityWeek Coverage
    • My CVE‑2025‑49706 Analysis
    • Wiz Threat Intel

    👨‍💻 About the Author

    I'm a cybersecurity practitioner focused on offensive security, exploit analysis, and red team operations. I’ve ranked in the top 2% on TryHackMe and published security tools like KeySentry, ShadowHash, and PixelPhantomX. I hold certifications like CEH, Security+, and the IIT Kanpur Red Team Certificate, and write regularly for InfoSec WriteUps and other security platforms.

    🔗 GitHub: @AdityaBhatt3010
    ✍️ Medium: @adityabhatt3010
    💼 LinkedIn: Aditya Bhatt


    Download Tool