Deserialization of Untrusted Data in Microsoft SharePoint Server - CVE-2025-53770
Published: July 20, 2025 / Updated: November 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, the vulnerability is being exploited in the wild.
Affected software
How to mitigate CVE-2025-53770
Links to Public Exploits and PoC-codes
- Exploit #12102 - CVE-2025-53770 (November 14, 2025)
- Exploit #12086 - OurSharePoint-CVE-2025-53770 (November 7, 2025)
- Exploit #11989 - SharePoint-CVE-2025-53770-POC (September 26, 2025)
- Exploit #11983 - CVE-2025-53770-Exploit (?️ Exploit Microsoft SharePoint WebPart Injection vulnerabilities for .NET deserialization and remote code execution using ToolPane.aspx.) (September 24, 2025)
- Exploit #11964 - CVE-2025-53770 (September 17, 2025)
- Exploit #11915 - CVE-2025-53770 (August 30, 2025)
- Exploit #11859 - CVE-2025-53770 (August 22, 2025)
- Exploit #11846 - CVE-2025-53770 (August 8, 2025)
- Exploit #11835 - CVE-2025-53770 (August 8, 2025)
- Exploit #11806 - CVE-2025-53770-SharePoint-RCE (Exploit & research for CVE‑2025‑53770 – a zero‑day remote code execution vulnerability in Microsoft SharePoint (on‑premises).) (July 24, 2025)
- Exploit #11804 - CVE-2025-53770-Exploit (July 24, 2025)