TGViewer
Vulnerability Management and more Vulnerability Management and more @avleonovcom · 2.89K subscribers
Post #1605 637
About Remote Code Execution - Microsoft SharePoint "ToolShell" (CVE-2025-49704) vulnerability. This vulnerability is from the Microsoft's July Patch Tuesday. SharePoint is a web application developed by Microsoft for corporate intranet portals, document management, and collaborative work. Deserialization of untrusted data in the DataSetSurrogateSelector class leads to remote code execution in the context of the SharePoint web server process. Exploitation requires authentication, obtainable for example via CVE-2025-49706 ("ToolShell" chain).

🔬 The "ToolShell" chain was demonstrated by the Viettel Cyber Security team at Pwn2Own Berlin, May 15–17, 2025 (prize $100,000).

👾 Signs of exploitation in the wild have been observed since July 7. The vulnerability was added to CISA KEV on July 22.

🛠 Public exploits available on GitHub since July 21.

➡️ Later "ToolShell" vulnerabilities: CVE-2025-53770 and CVE-2025-53771.

На русском

@avleonovcom #SharePoint #Microsoft #ToolShell
More from @avleonovcom
  1. Sep 14, 2026About Authentication Bypass - Microsoft SharePoint (CVE-2026-55040) vulnerability. SharePo…
  2. Sep 11, 2026About Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-688…
  3. Sep 9, 2026September Microsoft Patch Tuesday. A total of 973 vulnerabilities were addressed - more th…
  4. Sep 7, 2026About Remote Code Execution - TeamCity (CVE-2026-63077) vulnerability. TeamCity is a propr…
  5. Sep 4, 2026About Remote Code Execution - TrueConf Server (CVE-2026-72529, CVE-2026-72530) vulnerabili…
  6. Aug 31, 2026About Remote Code Execution - Zimbra Collaboration (CVE-2026-73570) vulnerability. Zimbra…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →