¡¾·ì϶¹«¸æ¡¿Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-53770)
°ä²¼¹¦·ò 2025-07-21Ò»¡¢¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-53770 | ||
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-07-21 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
Microsoft SharePointÊÇÒ»¿îÆóÒµ¼¶ºÏ×÷ƽ̨£¬£¬£¬Ö¼ÔÚÍÆ½øÐÅÏ¢¹²Ïí¡¢¡¢¡¢ÄÚÈÝÖÎÀíºÍÍŶӺÏ×÷¡£ËüÖ§³ÖÎĵµÖÎÀí¡¢¡¢¡¢ÄÚÈݰ䲼¡¢¡¢¡¢Êý¾Ý¹²ÏíºÍÄÚ²¿ÍøÕ¾´´½¨¡£SharePointÌṩÁË׳´óµÄ¹¤×÷Á÷Ö°ÄÜ£¬£¬£¬ÔÊÐíÓû§ÖÎÀíÏîÄ¿¡¢¡¢¡¢¹¤×÷ºÍ¹¤×÷Á÷£¬£¬£¬ÌáÉýÍŶÓЧÄÜ¡£Óû§Äܹ»´´½¨¡¢¡¢¡¢´æ´¢ºÍ¹²ÏíÎĵµ¡¢¡¢¡¢»ã±¨µÈ¶àÖÖÀàÐ͵ÄÐÅÏ¢£¬£¬£¬Ö§³Ö¶àÖÖȨÏÞÖÎÀíºÍ°²È«½ÚÖÆ¡£Ëü¿ÉÓëÆäËûMicrosoft 365¹¤¾ß£¨ÈçOutlook¡¢¡¢¡¢TeamsºÍOneDrive£©¼¯³É£¬£¬£¬¿í·ºÀûÓÃÓÚ×éÖ¯ÄڵĺÏ×÷ºÍÐÅÏ¢ÖÎÀí¡£
2025Äê7ÔÂ21ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Microsoft SharePointÖеÄÑÏÖØÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-53770£©¡£¸Ã·ì϶ԴÓÚSharePoint´¦ÖÃHTTP RefererͷʱµÄȱµã£¬£¬£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬Î´¾ÈÏÖ¤Ö´ÐжñÒâ´úÂë¡£·ì϶½áºÏÁËCVE-2025-49706ºÍCVE-2025-49704£¬£¬£¬ÐγÉÃûΪToolShellµÄ¹¥»÷Á´£¬£¬£¬ÀûÓÃSharePointµÄ·´ÐòÁл¯·ì϶ִÐÐÔ¶³Ì´úÂë¡£¹¥»÷Õßͨ¹ýÌáÈ¡SharePoint·þÎñÆ÷µÄÃÜÔ¿×ÊÁÏ£¨ÈçValidationKeyºÍDecryptionKey£©£¬£¬£¬¿ÉÄÜÌìÉúÓÐЧµÄ¹¥»÷ÔØºÉ£¨Èç__VIEWSTATE£©£¬£¬£¬½øÒ»²½½ÚÀñ·þÎñÆ÷£¬£¬£¬»ñµÃ³ÖÐø½Ó¼ûȨÏÞ¡£´Ë·ì϶Òѱ»¿í·ºÀûÓ㬣¬£¬¶à¸öSharePoint·þÎñÆ÷ÔÚ2025Äê7ÔÂ18ÈÕ±»¹¥Ï£¬£¬£¬·ì϶ÆÀ·Ö9.8·Ö£¬£¬£¬·ì϶¼¶±ðÑÏÖØ¡£
¶þ¡¢¡¢¡¢Ó°ÏìÁìÓò
Èý¡¢¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


¾©¹«Íø°²±¸11010802024551ºÅ