Collected research
SharePoint ToolShell – One Request PreAuth RCE chain CVE-2025-53770
A one-request pre-auth remote code execution chain in SharePoint: a Referer of the SignOut page skips the anonymous-access check, and ToolPane.aspx parses attacker-supplied control markup before the form-digest check. A type-name parsing flaw treats unqualified generic names as object, defeating the deserialization allow-list.
Record
- Researcher
- @_l0gg and khoadha
- Published by
- Blog of Viettel Cyber Security
- Date
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @_l0gg and khoadha, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .