A newly released Metasploit module highlights the critical threat posed by an actively exploited remote code execution (RCE) vulnerability in Microsoft SharePoint Server—CVE-2025-53770. The flaw, rated CVSS 9.8, enables attackers to remotely execute arbitrary code by exploiting unsafe deserialization in on-premise SharePoint deployments.
Stephen Fewer, Principal Security Researcher at Rapid7, developed and released the exploit module, now publicly available on the Metasploit Framework GitHub repository. The vulnerability targets Microsoft SharePoint Server installations where deserialization of untrusted data occurs, allowing attackers to trigger remote code execution over a network.
Microsoft acknowledged the issue in a July 20 security advisory, warning that the flaw has already been exploited in active attacks against on-premise SharePoint Server customers. The company emphasized that SharePoint Online (Microsoft 365) remains unaffected.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-53770 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring Federal Civilian Executive Branch agencies to apply the necessary patches no later than July 21, 2025.
Microsoft advises SharePoint Server customers to take the following mitigation steps immediately:
- Upgrade to one of the following secure versions:
- SharePoint Server 2019 (16.0.10417.20027)
- SharePoint Enterprise Server 2016 (16.0.5508.1000)
- SharePoint Server Subscription Edition
- Apply the latest cumulative security updates.
- Enable Antimalware Scan Interface (AMSI) in Full Mode for SharePoint.
- Use Microsoft Defender for Endpoint or equivalent EDR solution.
- Rotate the SharePoint ASP.NET machine keys after updates.
- Restart IIS services on all SharePoint servers post-patching.
“If you cannot enable AMSI, you will need to rotate your keys after you install the new security update,” Microsoft emphasized in its official guidance.
The public availability of a Metasploit module significantly lowers the barrier for exploitation. This amplifies the urgency for SharePoint administrators to act swiftly, especially in enterprise environments still relying on on-premise deployments.
With attack chains like ToolShell already observed in the wild, unpatched systems remain prime targets for threat actors. Organizations must not only patch but also monitor for signs of compromise, particularly unusual ASP.NET behaviors or suspicious file traversals.
Related Posts:
- SharePoint Server Under Active Zero-Day Attack (CVE-2025-53770, CVSS 9.8), No Patch Yet!
- Microsoft’s September Patch Tuesday: A Patchwork of Urgency with 4 Zero-Days Under Attack
- Craft CMS Zero-Day CVE-2025-32432 Exploited with Metasploit Module Now Public
- CVE-2024-38094 Exploited: Attackers Gain Domain Access via Microsoft SharePoint Server
- Critical AWS Amplify Studio Flaw Allows Code Execution – Update Now!
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.