Vulnerability record · CVE-2025-53770 · published 20 July 2025
CVE-2025-53770: Microsoft SharePoint Server deserialization RCE under active exploitation
Microsoft · Sharepoint Server
On-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft states an exploit exists in the wild and that a comprehensive update is still in preparation, so defenders must rely on mitigations in the interim. The flaw is critical because it is remotely reachable without credentials and is already being exploited at scale.
Description
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network RCE in internet-facing SharePoint with confirmed in-the-wild exploitation, KEV listing, near-certain EPSS score and known ransomware use.
What it is
On-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft states an exploit exists in the wild and that a comprehensive update is still in preparation, so defenders must rely on mitigations in the interim. The flaw is critical because it is remotely reachable without credentials and is already being exploited at scale.
Impact
An attacker gains remote code execution on the SharePoint server, which typically means full control of the host and access to connected content, credentials and downstream systems. CISA's KEV entry notes known ransomware campaign use, so follow-on encryption or extortion is a realistic outcome.
Attack surface
Reached over the network against internet-facing on-premises SharePoint Server; the CVSS vector shows no privileges and no user interaction required. No specific endpoint or component is named in the record, so the exact entry point is not stated.
Exploitation
Active exploitation is confirmed: CISA added it to KEV on 2025-07-20 with a 2025-07-21 due date and known ransomware use, EPSS 30-day probability is 0.99998, and multiple references carry Exploit tags.
What to do
- Apply the Microsoft update as soon as it is released; until then follow the MSRC customer guidance and CISA alert mitigations exactly.
- Disconnect or isolate internet-facing SharePoint Server instances that are end-of-life or end-of-service, including SharePoint Server 2013 and earlier, per CISA's required action.
- Restrict or block external access to SharePoint until mitigations are in place, and apply the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable.
- Rotate SharePoint machine keys and any credentials or secrets that may have been exposed on affected servers.
- Review SharePoint servers for signs of prior compromise before restoring normal exposure.
Detection
- Hunt web server and SharePoint logs for anomalous POST requests or deserialization-related activity from unexpected external sources.
- Monitor for unexpected child processes spawned by SharePoint worker processes (w3wp.exe), a common post-exploitation signal for web shells.
- Scan the SharePoint web root and layout directories for newly written or modified files such as web shells.
- Alert on outbound connections from SharePoint servers to unfamiliar hosts, which may indicate command-and-control or data staging.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-53770 to the Known Exploited Vulnerabilities catalog on 20 July 2025 as "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. Federal deadline 21 July 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-53770 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-53770), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.