CVE-2025-53770

9.8 CISA KEV

Microsoft · SharePoint Server

A critical deserialization vulnerability in on-premises Microsoft SharePoint Server allows unauthenticated remote code execution.

Executive summary

This critical vulnerability, known as ToolShell, allows unauthenticated remote code execution in Microsoft SharePoint Server and is currently being exploited in the wild.

Vulnerability

The flaw involves the deserialization of untrusted data within on-premises SharePoint Server components, which enables an unauthenticated attacker to execute arbitrary code over a network. This vulnerability serves as a patch bypass for a previously identified issue and facilitates full system compromise.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this vulnerability, as it requires no user interaction or authentication to achieve remote code execution. Successful exploitation results in total system compromise, potentially leading to unauthorized data exfiltration, lateral movement within the network, and complete loss of service availability. Given the active exploitation of this flaw, organizations face a high risk of targeted attacks against critical infrastructure and sensitive corporate data.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately: KB5002760 for SharePoint 2016, KB5002754 for SharePoint 2019, and KB5002768 for SharePoint Server Subscription Edition.

Proactive Monitoring: Monitor server logs for anomalous deserialization attempts, unexpected process spawning from the SharePoint service account, and unauthorized network connections originating from SharePoint servers.

Compensating Controls: Configure AMSI integration in SharePoint and deploy Microsoft Defender Antivirus on all SharePoint hosts. If patches cannot be applied immediately, disconnect public-facing SharePoint servers from the internet to prevent unauthenticated exploitation.

Exploitation status

Public Exploit Available: Yes, a weaponized exploit exists, including entries in Metasploit and ExploitDB, alongside multiple public Proof-of-Concept repositories on GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability, the confirmed active exploitation, and the availability of weaponized exploit code, organizations must prioritize the immediate installation of the corresponding security updates. Failure to patch these systems leaves them exposed to complete compromise by remote, unauthenticated attackers. Once updates are applied, ensure that additional security measures such as AMSI integration and machine key rotation are performed to finalize the remediation process.

More Microsoft CVEs

Sources