
Exploit for CVE-2025-53770, a critical SharePoint RCE via authentication bypass and unsafe deserialization, enabling web shell deployment and machine key theft for persistent server compromise.
CVE-2025-53770 is a critical remote code execution (RCE) vulnerability affecting Microsoft SharePoint Server 2016, 2019, and Subscription Edition (on-premises only, not SharePoint Online). Attackers can bypass authentication and achieve full server control by exploiting a logic flaw and unsafe deserialization. This exploit chain—publicly known as "ToolShell"—has been observed in active attacks.
/_layouts/15/ToolPane.aspx?DisplayMode=EditReferer: /_layouts/SignOut.aspx
spinstall0.aspx) to the SharePoint system directory.ValidationKeyDecryptionKeysequenceDiagram
participant Attacker
participant SharePoint Server
Attacker->>SharePoint Server: POST /ToolPane.aspx (with fake Referer)
SharePoint Server-->>Attacker: Grants admin access (auth bypass)
Attacker->>SharePoint Server: Uploads malicious web shell
Attacker->>SharePoint Server: Executes web shell to read config
SharePoint Server-->>Attacker: Returns ValidationKey and DecryptionKey
Attacker->>SharePoint Server: Sends forged, signed payloads (persistent RCE)
This document is for research and defensive purposes only. Do not attempt exploitation on systems you do not own or have explicit authorization to test.