
CVE-2025-53770용 익스플로잇: 인증 우회와 안전하지 않은 역직렬화를 통한 치명적인 SharePoint RCE로, 지속적인 서버 침해를 위해 웹 셸 배포 및 머신 키 탈취를 가능하게 합니다.
CVE-2025-53770는 Microsoft SharePoint Server 2016, 2019 및 Subscription Edition(온-프레미스 전용, SharePoint Online 제외)에 영향을 미치는 치명적인 원격 코드 실행(RCE) 취약점입니다. 공격자는 논리적 결함과 안전하지 않은 역직렬화를 악용하여 인증을 우회하고 서버를 완전히 장악할 수 있습니다. "ToolShell"로 알려진 이 익스플로잇 체인은 실제 공격에서 관찰되었습니다.
/_layouts/15/ToolPane.aspx?DisplayMode=EditReferer: /_layouts/SignOut.aspx
spinstall0.aspx)을 SharePoint 시스템 디렉터리에 업로드합니다.ValidationKeyDecryptionKeysequenceDiagram
participant Attacker
participant SharePoint Server
Attacker->>SharePoint Server: POST /ToolPane.aspx (with fake Referer)
SharePoint Server-->>Attacker: Grants admin access (auth bypass)
Attacker->>SharePoint Server: Uploads malicious web shell
Attacker->>SharePoint Server: Executes web shell to read config
SharePoint Server-->>Attacker: Returns ValidationKey and DecryptionKey
Attacker->>SharePoint Server: Sends forged, signed payloads (persistent RCE)
이 문서는 연구 및 방어 목적으로만 제공됩니다. 소유하지 않거나 명시적 테스트 권한이 없는 시스템에서 익스플로잇을 시도하지 마십시오.