## https://sploitus.com/exploit?id=D73E5DBC-629E-503C-9E81-BAA5D042E862
# SharePoint ToolPane RCE Exploit

[](https://github.com)
[](https://www.python.org)
[](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770)
[](#disclaimer)
> **Security research toolkit for testing SharePoint ToolPane vulnerabilities**
[Overview](#overview) β’ [Features](#features) β’ [Getting started](#getting-started) β’ [Usage](#usage) β’ [Project structure](#project-structure)
This repository contains proof-of-concept exploits and analysis tools for the SharePoint ToolPane vulnerability (CVE-2025-53770). The project demonstrates exploitation techniques including authentication bypass and unsafe deserialization vulnerabilities affecting Microsoft SharePoint Server.
> [!WARNING]
> **For authorized security testing only.** This project is intended for educational purposes, penetration testing, and security research on systems you own or have explicit permission to test.
## Overview
CVE-2025-53770 is a critical vulnerability in Microsoft SharePoint Server that allows unauthenticated remote code execution through a combination of authentication bypass and unsafe deserialization. This vulnerability affects SharePoint Server 2019 and is particularly dangerous as it requires no authentication.
The vulnerability chain includes:
- **CVE-2025-49706** - Authentication bypass affecting ToolPane.aspx
- **CVE-2025-53771** - Patch bypass for CVE-2025-49706
- **CVE-2025-49704** - Unsafe deserialization vulnerability
- **CVE-2025-53770** - Patch bypass targeting different endpoints
## Features
- **Multiple exploitation methods** - Python and cURL implementations
- **Target scanning** - Automated vulnerable version detection
- **Payload analysis** - Tools to decode and analyze exploit payloads
- **Comprehensive documentation** - Detailed vulnerability analysis and exploitation guidance
- **Real-world testing** - Proven against multiple SharePoint versions
## Getting started
### Prerequisites
- **Python 3.x** with `requests` and `urllib3` libraries
- **Network access** to target SharePoint servers
- **Authorization** to test target systems
## Usage
### Scanning for vulnerable targets
Use the scanner to identify potentially vulnerable SharePoint installations:
```bash
python3 scanner/scanner.py
```
### Running the exploit
#### Python exploitation
Execute the main Python exploit against a target:
```bash
python3 exploit/exploit.py
```
Example output:
```
[+] Targeting: http://192.168.1.100
[+] Sending exploit payload...
[+] Response Status: 200
[+] Response Length: 1234 bytes
```
#### cURL testing
Test using the provided cURL commands:
```bash
# Review the cURL file for specific commands
cat metasploit_ref/cURL
```
### Analyzing responses
Use the analysis tool to decode and examine exploit responses:
```bash
python3 analysis/analyse.py
```
This tool extracts and decodes base64-encoded payloads from captured traffic.
## Project structure
```
βββ analysis/
β βββ analyse.py # Payload analysis and decoding tools
βββ exploit/
β βββ exploit.py # Main Python RCE exploit
βββ metasploit_ref/
β βββ cURL # cURL command examples
β βββ sharepoint_toolpane_rce.md # Detailed vulnerability documentation
β βββ sharepoint_toolpane_rce.rb # Ruby reference implementation
βββ out/ # Analysis output directory
βββ scanner/
β βββ scanner.py # Vulnerability scanner
βββ README.md # This file
```
## Vulnerable versions
The following SharePoint Server versions are confirmed vulnerable:
- SharePoint Server 2019 `16.0.10337.12109` (RTM version)
- SharePoint Server 2019 `16.0.10417.20018` (June 2025 patch level)
- SharePoint Server 2019 `16.0.10417.20027` (July 2025 patch level)*
*The July 2025 patch level may still be exploitable unless administrators have manually performed configuration updates.
## Disclaimer
> [!CAUTION]
> **This project is provided for educational and authorized security testing purposes only.**
>
> - Only test systems you own or have explicit written permission to test
> - Unauthorized testing of systems may violate local, state, and federal laws
> - Users are solely responsible for ensuring compliance with applicable laws
> - The authors assume no liability for misuse of this software
## Resources
- [CVE-2025-53770 Details](https://cve.mitre.org)
- [Microsoft Security Advisory](https://msrc.microsoft.com)
- [SharePoint Security Best Practices](https://docs.microsoft.com/sharepoint/security)
---
β If this project helps your security research, consider starring it on GitHub!