CVE-2025-53771 is an improper authentication vulnerability in Microsoft Office SharePoint that allows an unauthorized network attacker to perform spoofing. Rated with a CVSS score of 6.5 (Medium) and a high FAUCET Risk Score of 80.0, this flaw has low attack complexity and requires no privileges or user interaction, leading to low confidentiality and integrity impacts directly. This vulnerability is actively exploited in the wild, often as part of a chain leading to Remote Code Execution (RCE) attacks, and is listed on the Hot List. Public exploit modules, including a Metasploit module for ToolShell RCE, are available, and it has generated significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.18526.20508CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.