CVE-2025-53770 and CVE-2025-53771: Actively Exploited SharePoint Vulnerabilities
July 22, 2025, 9:29 a.m.
Description
Two critical vulnerabilities, CVE-2025-53770 and CVE-2025-53771, are affecting Microsoft SharePoint Servers, enabling attackers to upload malicious files and extract cryptographic secrets. These flaws are evolutions of previously patched vulnerabilities, CVE-2025-49704 and CVE-2025-49706, which were incompletely remediated. Exploit attempts have been observed across various industries, including finance, education, energy, and healthcare. Microsoft has released patches for SharePoint Subscription Edition and Server 2019, with a patch for Server 2016 pending. The vulnerabilities allow for unauthenticated remote code execution through advanced deserialization techniques and ViewState abuse. Active exploitation in the wild has been confirmed, compromising on-premises SharePoint environments globally.
Tags
Date
- Created: July 22, 2025, 9:04 a.m.
- Published: July 22, 2025, 9:04 a.m.
- Modified: July 22, 2025, 9:29 a.m.
Indicators
- b336f936be13b3d01a8544ea3906193608022b40c28dd8f1f281e361c9b64e93
- 27c45b8ed7b8a7e5fff473b50c24028bd028a9fe8e25e5cea2bf5e676e531014
- 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514
- 8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2
- 96.9.125.147
- 104.238.159.149
- 107.191.58.76
- 103.186.30.186
Attack Patterns
Additional Informations
- Healthcare
- Energy
- Education
- Finance