¡¾Îó²îͨ¸æ¡¿Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-53770)
Ðû²¼Ê±¼ä 2025-07-21Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-53770 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-07-21 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Microsoft SharePointÊÇÒ»¿îÆóÒµ¼¶Ð×÷ƽ̨£¬Ö¼ÔÚÔö½øÐÅÏ¢¹²Ïí¡¢ÄÚÈÝÖÎÀíºÍÍŶÓÐ×÷¡£ËüÖ§³ÖÎĵµÖÎÀí¡¢ÄÚÈÝÐû²¼¡¢Êý¾Ý¹²ÏíºÍÄÚ²¿ÍøÕ¾½¨Éè¡£SharePointÌṩÁËǿʢµÄÊÂÇéÁ÷¹¦Ð§£¬ÔÊÐíÓû§ÖÎÀíÏîÄ¿¡¢Ê¹ÃüºÍÊÂÇéÁ÷£¬ÌáÉýÍŶÓЧÂÊ¡£Óû§¿ÉÒÔ½¨Éè¡¢´æ´¢ºÍ¹²ÏíÎĵµ¡¢±¨¸æµÈ¶àÖÖÀàÐ͵ÄÐÅÏ¢£¬Ö§³Ö¶àÖÖȨÏÞÖÎÀíºÍÇå¾²¿ØÖÆ¡£Ëü¿ÉÓëÆäËûMicrosoft 365¹¤¾ß£¨ÈçOutlook¡¢TeamsºÍOneDrive£©¼¯³É£¬ÆÕ±éÓ¦ÓÃÓÚ×éÖ¯ÄÚµÄÐ×÷ºÍÐÅÏ¢ÖÎÀí¡£
2025Äê7ÔÂ21ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Microsoft SharePointÖеÄÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-53770£©¡£¸ÃÎó²îÔ´ÓÚSharePoint´¦Öóͷ£HTTP RefererͷʱµÄȱÏÝ£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬Î´¾ÈÏÖ¤Ö´ÐжñÒâ´úÂë¡£Îó²îÍŽáÁËCVE-2025-49706ºÍCVE-2025-49704£¬ÐγÉÃûΪToolShellµÄ¹¥»÷Á´£¬Ê¹ÓÃSharePointµÄ·´ÐòÁл¯Îó²îÖ´ÐÐÔ¶³Ì´úÂë¡£¹¥»÷Õßͨ¹ýÌáÈ¡SharePoint·þÎñÆ÷µÄÃÜÔ¿ÖÊÁÏ£¨ÈçValidationKeyºÍDecryptionKey£©£¬Äܹ»ÌìÉúÓÐÓõĹ¥»÷ÔØºÉ£¨Èç__VIEWSTATE£©£¬½øÒ»²½¿ØÖÆ·þÎñÆ÷£¬»ñµÃÒ»Á¬»á¼ûȨÏÞ¡£´ËÎó²îÒѱ»ÆÕ±éʹÓ㬶à¸öSharePoint·þÎñÆ÷ÔÚ2025Äê7ÔÂ18ÈÕ±»¹¥ÏÝ£¬Îó²îÆÀ·Ö9.8·Ö£¬Îó²î¼¶±ðÑÏÖØ¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


¾©¹«Íø°²±¸11010802024551ºÅ