New SharePoint Vulnerability Scanner Targets CVE-2025-53770

An open-source scanner to help organizations identify SharePoint servers vulnerable to CVE-2025-53770, a critical unauthenticated remote code execution vulnerability that has been actively exploited in the wild.

The tool, developed by Belgian cybersecurity freelancer hazcod and published on GitHub, provides a quick method for administrators to assess their exposure to this severe security vulnerability .

CVE-2025-53770 represents a significant security threat to organizations running on-premises SharePoint servers.

The vulnerability allows attackers to achieve remote code execution without authentication by exploiting the SharePoint ToolBox widget functionality.

According to Microsoft’s security advisory, the vulnerability affects SharePoint servers that lack the KB5002768 and KB5002754 security patches.

The vulnerability appears to build upon a previously disclosed SharePoint vulnerability, CVE-2025-49706, demonstrating how threat actors continue to evolve their attack techniques against Microsoft’s collaboration platform.

The exploit mechanism involves sending specially crafted HTTP POST requests to the SharePoint server’s ToolPane.aspx endpoint.

Attackers can inject malicious ASP.NET directives and server-side markup through compressed and base64-encoded payloads, ultimately triggering deserialization-based remote code execution.

Security researchers have observed threat actors leveraging this vulnerability to execute PowerShell commands on compromised systems, highlighting the severity of the security gap.

SharePoint Vulnerability

The newly released scanner, available on GitHub, offers organizations a straightforward method to test their SharePoint deployments for vulnerability.

The tool works by attempting to inject a harmless marker into the SharePoint ToolBox widget and analyzing the server response to determine if the injection was successful.

Recent commits show active development, with updates made as recently as three hours ago to improve the tool’s functionality, including dependency updates and bug fixes.

The scanner provides multiple operational modes, including basic vulnerability detection and SharePoint version extraction capabilities.

Users can run the tool with debug logging enabled to gather additional information about their SharePoint environment.

The developer emphasizes that the scanner uses only harmless test payloads designed to prove exploitability without causing damage to target systems, making it suitable for legitimate security testing purposes.

On-Premises SharePoint Users

According to Report, Organizations running on-premises SharePoint servers face immediate security risks if they have not applied the necessary security patches.

The vulnerability specifically affects SharePoint Server environments that lack the KB5002768 and KB5002754 updates.

Given that active exploitation has been observed in the wild, administrators should prioritize patching efforts and conduct vulnerability assessments using available tools.

The scanner’s release comes at a critical time, as the developer notes that the code was created through reverse-engineering malicious payloads observed during actual attacks.

This real-world context underscores the urgent need for organizations to assess their exposure and implement appropriate security measures.

While the tool provides valuable testing capabilities, the developer includes a disclaimer about potential risks, emphasizing that users should exercise caution and understand the implications of vulnerability testing in their environments.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mayura
Mayura
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Trending News

Related Stories