
Unauthenticated remote code execution exploit for Microsoft SharePoint Server 2019 via unsafe .NET deserialization in ToolPane.aspx. Python-based PoC targeting Scorecard:ExcelDataSet control.
Exploit Author: Agampreet Singh
Tool: RedRoot (https://github.com/Agampreet-Singh/RedRoot)
Date: August 7, 2025
Tested On: SharePoint Server 2019 (v16.0.10383.20020) on Windows Server 2019
CVE-ID: CVE-2025-53770
Vulnerability Type: Unauthenticated Remote Code Execution (RCE)
Attack Vector: Unsafe .NET deserialization viaScorecard:ExcelDataSetinToolPane.aspx
An unauthenticated remote code execution vulnerability was discovered in Microsoft SharePoint Server 2019, specifically within the ToolPane.aspx endpoint. This flaw arises from unsafe deserialization of the Scorecard:ExcelDataSet control, which allows attackers to inject a GZip-compressed and Base64-encoded .NET object that gets deserialized server-side, leading to arbitrary code execution.
16.0.10383.20020python3 cve-2025-53770.py https://target-sharepoint.com