{"id":26360,"date":"2025-11-14T20:41:59","date_gmt":"2025-11-14T20:41:59","guid":{"rendered":"http:\/\/localhost\/?p=26360"},"modified":"2025-11-14T20:41:59","modified_gmt":"2025-11-14T20:41:59","slug":"about-remote-code-execution-microsoft-sharepoint-toolshell-cve-2025-49704-vulnerability","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=26360","title":{"rendered":"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-15T02:05:07&#8243;,&#8221;description&#8221;:&#8221;![About Remote Code Execution &#8211; Microsoft SharePoint ToolShell \\\\(CVE-2025-49704\\\\) vulnerability](https:\/\/avleonov.com\/wp-content\/uploads\/2025\/11\/photo_877@13-11-2025_16-56-56.jpg)\\n\\n**About Remote Code Execution &#8211; Microsoft SharePoint \\&#8221;ToolShell\\&#8221; (CVE-2025-49704) vulnerability.** This vulnerability is from the Microsoft&#8217;s July Patch Tuesday. SharePoint is a web application developed by Microsoft for corporate intranet portals, document management, and collaborative work. Deserialization of untrusted data in the DataSetSurrogateSelector class leads to remote code execution in the context of the SharePoint web server process. Exploitation requires authentication, obtainable for example via CVE-2025-49706 (\\&#8221;ToolShell\\&#8221; chain).\\n\\n![\ud83d\udd2c](https:\/\/s.w.org\/images\/core\/emoji\/16.0.1\/72&#215;72\/1f52c.png) The \\&#8221;ToolShell\\&#8221; chain was demonstrated by the Viettel Cyber Security team at Pwn2Own Berlin, May 15\u201317, 2025 (prize $100,000).\\n\\n![\ud83d\udc7e](https:\/\/s.w.org\/images\/core\/emoji\/16.0.1\/72&#215;72\/1f47e.png) Signs of exploitation in the wild have been observed since July 7. The vulnerability was added to CISA KEV on July 22.\\n\\n![\ud83d\udee0](https:\/\/s.w.org\/images\/core\/emoji\/16.0.1\/72&#215;72\/1f6e0.png) Public exploits available on GitHub since July 21.\\n\\n![\u27a1](https:\/\/s.w.org\/images\/core\/emoji\/16.0.1\/72&#215;72\/27a1.png) Later \\&#8221;ToolShell\\&#8221; vulnerabilities: CVE-2025-53770 and CVE-2025-53771.\\n\\n\u041d\u0430 \u0440\u0443\u0441\u0441\u043a\u043e\u043c&#8221;,&#8221;published&#8221;:&#8221;2025-11-13T13:56:56&#8243;,&#8221;modified&#8221;:&#8221;2025-11-13T13:56:56&#8243;,&#8221;type&#8221;:&#8221;avleonov&#8221;,&#8221;title&#8221;:&#8221;About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;AVLEONOV:22CEEC8D500265AF898E23D054125ECF&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-49704&#8243;,&#8221;CVE-2025-49706&#8243;,&#8221;CVE-2025-53770&#8243;,&#8221;CVE-2025-53771&#8243;],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.8,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/avleonov.com\/2025\/11\/13\/1605-about-remote-code-execution-microsoft-sharepoint\/&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-15T02:05:07&#8243;,&#8221;description&#8221;:&#8221;![About Remote Code Execution &#8211; Microsoft SharePoint ToolShell \\\\(CVE-2025-49704\\\\) vulnerability](https:\/\/avleonov.com\/wp-content\/uploads\/2025\/11\/photo_877@13-11-2025_16-56-56.jpg)\\n\\n**About Remote Code Execution &#8211; Microsoft SharePoint \\&#8221;ToolShell\\&#8221; (CVE-2025-49704) vulnerability.** This vulnerability is from the Microsoft&#8217;s&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[155,9,6,8,35,12,13,7,11,5],"class_list":["post-26360","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-avleonov","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=26360\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-15T02:05:07&#8243;,&#8221;description&#8221;:&#8221;![About Remote Code Execution &#8211; Microsoft SharePoint ToolShell \\(CVE-2025-49704\\) vulnerability](https:\/\/avleonov.com\/wp-content\/uploads\/2025\/11\/photo_877@13-11-2025_16-56-56.jpg)nn**About Remote Code Execution &#8211; Microsoft SharePoint &#8221;ToolShell&#8221; (CVE-2025-49704) vulnerability.** This vulnerability is from the Microsoft&#8217;s...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=26360\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-14T20:41:59+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF\",\"datePublished\":\"2025-11-14T20:41:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360\"},\"wordCount\":348,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"avleonov\",\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=26360#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360\",\"name\":\"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-14T20:41:59+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=26360\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26360#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=26360","og_locale":"en_US","og_type":"article","og_title":"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-15T02:05:07&#8243;,&#8221;description&#8221;:&#8221;![About Remote Code Execution &#8211; Microsoft SharePoint ToolShell \\(CVE-2025-49704\\) vulnerability](https:\/\/avleonov.com\/wp-content\/uploads\/2025\/11\/photo_877@13-11-2025_16-56-56.jpg)nn**About Remote Code Execution &#8211; Microsoft SharePoint &#8221;ToolShell&#8221; (CVE-2025-49704) vulnerability.** This vulnerability is from the Microsoft&#8217;s...","og_url":"https:\/\/zero.redgem.net\/?p=26360","og_site_name":"zero redgem","article_published_time":"2025-11-14T20:41:59+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=26360#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=26360"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF","datePublished":"2025-11-14T20:41:59+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=26360"},"wordCount":348,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["avleonov","CRITICAL","CVE","CVSS","CVSS-9.8","exploit","news","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=26360#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=26360","url":"https:\/\/zero.redgem.net\/?p=26360","name":"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-14T20:41:59+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=26360#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=26360"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=26360#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"About Remote Code Execution \u2013 Microsoft SharePoint \u201cToolShell\u201d (CVE-2025-49704) vulnerability_AVLEONOV:22CEEC8D500265AF898E23D054125ECF"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/26360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26360"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/26360\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}