Vulnerability Report

CVE-2025-53770

RCE CISA KEV Active

Title: Microsoft Sharepoint Server RCE

RCE

Proof Of Concept

PoC Available for CVE-2025-53770

CWE Category CWE-502
Published Date Jul 20, 2025
Modified Date Aug 04, 2026
Exploit Status Available
Score 9.8 CVSS v3.1
Exploit Probability (EPSS)
100.00%

Vulnerability Summary

CVE-2025-53770: Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CVSS v3.1
Source Entity [email protected]
Severity CRITICAL
9.8
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2025-53770 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/soltanali0/CVE-2025-53770-Exploit
View Code
GitHub https://github.com/peiqiF4ck/WebFrameworkTools-5.5-enhance
View Code
GitHub https://github.com/kaizensecurity/CVE-2025-53770
View Code
Exploit-DB https://www.exploit-db.com/exploits/52405
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

MODIFIED

Vulnerability data updated via NVD.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Stack

No specific products linked.