Microsoft SharePoint Zero-Day RCE Vulnerability (CVE-2025-53770)
BACKGROUND
CVSS Score: Base 9.8 Critical
A critical remote code execution vulnerability, tracked as CVE-2025-53770, has been
actively exploited in the wild. It targets on-premises Microsoft SharePoint Server
deployments. The flaw involves deserialization of untrusted data, allowing attackers to
execute arbitrary code remotely without authentication. This vulnerability has led to
mass attacks, compromising over 75 organizations, enabling threat actors to move
laterally, persist, and blend with legitimate SharePoint activity, making detection more
difficult.
Note: SharePoint Online (Microsoft 365) is not affected.
IMPACT
- Enables unauthorized attackers to execute code over a network.
- Bypasses identity controls, including Multi Factor Authentication (MFA) and Single Sign-On (SSO).
- Allows theft of MachineKey theft.
AFFECTED PRODUCTS
| Affected Products | Fixed Versions | |
| 1 | Microsoft SharePoint Server Subscription Edition | KB5002768 |
| 2 | Microsoft SharePoint Server 2019 | KB5002741 (16.0.10417.20027) |
| 3 | Microsoft SharePoint Server 2019 Core | KB5002754 |
| 4 | Microsoft SharePoint Enterprise Server 2016 | KB5002744 (16.0.5508.1000) |
| 5 | Microsoft SharePoint Server 2016 | Pending |
RECOMMENDATIONS
- To mitigate potential attacks, customers should:
- Use supported versions of on-premises SharePoint Server.
- Apply the latest security patches with immediate eect.
- Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an antivirus solution such as Microsoft Defender Antivirus.
- Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions
- Rotate SharePoint Server ASP.NET machine keys.
- NOTE: SharePoint Server 2016 users should monitor Microsoft’s update guidance
and apply patches once available.
REFERENCES
- https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepointvulnerability-
cve-2025-53770/ - https://support.microsoft.com/en-us/topic/description-of-the-security-updatefor-
sharepoint-server-2019-july-8-2025-kb5002741-d860f51b-fcdf-41e4-89de-
9ce487c06548 - https://support.microsoft.com/en-us/topic/description-of-the-security-updatefor-
sharepoint-enterprise-server-2016-july-8-2025-kb5002744-9196e240-c76d-
4bb0-b16c-6f7d6645a1f0 - https://www.microsoft.com/en-us/download/details.aspx?id=108285
- https://www.microsoft.com/en-us/download/details.aspx?id=108286
- https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releasesguidance-
exploitation-sharepoint-vulnerability-cve-2025-53770