
ToolShell scanner - CVE-2025-53770 and detection information
100% hacked together with all the tweets floating around with payloads and different attacks, so comes with zero warranty etc. The scanner is designed to identify vulnerable instances and has a config with known uses in the wild of exploitation, it's primarily designed for defensive use to identify vulnerable instances and allow you to patch things.
This scanner performs automated checks of SharePoint deployments by:
SP2013: WEBSER~1\15\ vs SP2016+: WEBSER~1\16\)git clone https://github.com/ZephrFish/CVE-2025-53770-Scanner
cd CVE-2025-53770-Scanner
pip install -r requirements.txt
Create a text file with target hosts (one per line):
sharepoint1.example.com
sharepoint2.example.net
internal-sp.company.local
Run the scanner:
python3 scanner.py -i hosts.txt
python3 scanner.py -i hosts.txt -o results.json -l scan.log -t 20 -v
| Option | Description | Default |
|---|---|---|
-i, --input | Path to host list file (required) | - |
-o, --output | Output file for results (.json, .csv, .txt) | None |
-l, --logfile | Log file path for detailed logging | None |
-t, --threads | Number of concurrent threads | 10 |
-v, --verbose | Enable verbose output and logging | False |
-o results.json)[
{
"host": "sharepoint.example.com",
"url": "https://sharepoint.example.com/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx",
"scan_time": "2025-07-21T10:30:00.123456",
"vulnerable": true,
"status_code": 200,
"response_size": 15432,
"error": null,
"response_time": 1.23
}
]
-o results.csv)Provides tabular data suitable for spreadsheet analysis with columns for all scan metrics.
-o results.txt)Human-readable format with vulnerability status and scan details.
CVE-2025-53770 targets a deserialization vulnerability in SharePoint's ExcelDataSet component that has been actively exploited in the wild. The scanner detects:
/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx with serialized payloadValidationKey|Validation|DecryptionKey|Decryption|CompatibilityMode
Example: [128-256 hex chars]|HMACSHA256|[48-96 hex chars]|AES|Framework45
spinstall0.aspx for persistent access and key extractionMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0/_layouts/SignOut.aspxThe scanner analyzes responses for:
$ python3 scanner.py -i corporate-sharepoint.txt -o vuln-results.json -l scan.log -v
Starting scan of 150 hosts with 10 threads...
Target CVE: CVE-2025-53770 (SharePoint ExcelDataSet deserialization)
Logging to: scan.log
Results will be saved to: vuln-results.json
[+] VULNERABLE [CRITICAL]: sp-prod-01.acme.local
[-] Not vulnerable: sp-dev-02.acme.local
[!] ERROR: offline-sp.acme.local - Connection timeout
[+] VULNERABLE [HIGH]: sp-legacy.acme.local
Progress: 50/150 (33.3%)
Progress: 100/150 (66.7%)
Progress: 150/150 (100.0%)
============================================================
SCAN COMPLETE
============================================================
Total hosts scanned: 150
Vulnerable hosts: 3
Success rate: 97.3%
VULNERABLE HOSTS (CVE-2025-53770):
CRITICAL - MACHINE KEY EXTRACTED (1 hosts):
• sp-prod-01.acme.local (Response time: 0.85s, Version: 2016+)
WARNING: IMMEDIATE ACTION REQUIRED: Machine keys compromised
HIGH CONFIDENCE (1 hosts):
• sp-legacy.acme.local (Response time: 1.23s, Version: 2013-2016)
LOW CONFIDENCE (1 hosts):
• sp-archive.acme.local (Response time: 2.10s, Version: Unknown)
Detailed results saved to: vuln-results.json
Enable verbose logging (-v) and log files (-l) for detailed troubleshooting:
tail -f scan.log
The scanner incorporates detection for confirmed exploitation patterns observed in active attacks:
POST /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx HTTP/1.1
Host: target.domain.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
Content-Length: 7699
Content-Type: application/x-www-form-urlencoded
Referer: /_layouts/SignOut.aspx
Connection: close
MSOTlPn_Uri=http%3A%2F%2F{{host}}%2F_controltemplates%2F15%2FAclEditor.ascx
&MSOTlPn_DWP=[ExcelDataSet payload with CompressedDataTable containing serialized exploit]