0333 032 8979 info@norsoc.com

Microsoft Sharepoint RCE (July 2025)

DATE ISSUED:
22/07/2025

SUBJECT:
Microsoft SharePoint allows remote code execution via specially crafted requests – CVE-2025-38023


OVERVIEW:
Multiple Vulnerabilities have been discovered in Microsoft SharePoint Server, which could allow for remote code execution. Microsoft SharePoint Server is a web-based collaborative platform that integrates with Microsoft Office. Successful exploitation of these vulnerabilities allows for unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network


THREAT INTELLIGENCE:
CISA is aware of active exploitation of CVE-2025-53770 and CVE-2025-53771 in the wild. This exploitation activity, publicly reported as “ToolShell,” provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network.


SYSTEMS AFFECTED:

  • Microsoft SharePoint Server Subscription Edition prior to security update KB5002768.
  • Microsoft SharePoint Server 2019 Core prior to security update KB5002754.
  • Microsoft SharePoint Server 2019 Language Pack prior to security update KB5002753
  • Microsoft SharePoint Enterprise Server 2016 prior to security update KB5002760.
  • Microsoft SharePoint Enterprise Server 2016 Language Pack prior to security update KB5002759.

TECHNICAL SUMMARY:

Multiple Vulnerabilities have been discovered in Microsoft SharePoint Server, which could allow for remote code execution.  Details of the vulnerability are as follows:

Tactic: Initial Access (TA0001):

Technique: Exploit Public-Facing Application (T1190):

  • Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. (CVE-2025-53770)
  • Improper limitation of a pathname to a restricted directory (patd traversal) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. (CVE-2025-53771)
    • These vulnerabilities are evolutions of previously patched flaws (CVE-2025-49704 and CVE-2025-49706), for which initial vendor-provided remediation was incomplete, enabling attackers to achieve unauthenticated RCE attacks through advanced deserialization techniques and ViewState abuse. Patches addressing these vulnerabilities were released by Microsoft on July 20. 

 Successful exploitation of these vulnerabilities allows for unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network


RECOMMENDATIONS:

  • Immediately apply Microsoft’s July 2025 security updates to all affected SharePoint servers

  • Restrict access to SharePoint administration interfaces from untrusted networks

  • Monitor for abnormal HTTP request patterns and post-authentication anomalies

  • Review audit logs for suspicious administrative activity

  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack
  • Architect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. Configure separate virtual private cloud (VPC) instances to isolate critical cloud systems

REFERENCES:

 

Book A Chat

If you want to discuss your cyber security more or ask us any questions please do book a free no obligation chat with us.