Security Research

CVE-2025-53770 SharePoint WebPart Injection Deserialization RCE: Active Exploitation Before Patch Day

#Vulnerability Analysis#Code Audit#Web Security#Malware
CVE-2025-53770 SharePoint WebPart Injection Deserialization RCE: Active Exploitation Before Patch Day

SharePoint treats WebPart rendering as “trusted internal”, but the ToolPane.aspx endpoint accepts unauthenticated POST — attackers construct a malicious WebPart payload that triggers a .NET deserialization gadget chain, executing arbitrary commands on the SharePoint Server without authentication, and Microsoft has confirmed it is being exploited in the wild.

Unlock to view this content.