¡¾·ì϶¹«¸æ¡¿Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-53770)
°ä²¼¹¦·ò 2025-07-21Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-53770 | ||
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-07-21 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
Microsoft SharePointÊÇÒ»¿îÆóÒµ¼¶ºÏ×÷ƽ̨£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍÆ½øÐÅÏ¢¹²Ïí¡¢ÄÚÈÝÖÎÀíºÍÍŶӺÏ×÷¡£¡£¡£¡£¡£¡£¡£ËüÖ§³ÖÎĵµÖÎÀí¡¢ÄÚÈݰ䲼¡¢Êý¾Ý¹²ÏíºÍÄÚ²¿ÍøÕ¾´´½¨¡£¡£¡£¡£¡£¡£¡£SharePointÌṩÁË׳´óµÄ¹¤×÷Á÷Ö°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§ÖÎÀíÏîÄ¿¡¢¹¤×÷ºÍ¹¤×÷Á÷£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÍŶÓЧÄÜ¡£¡£¡£¡£¡£¡£¡£Óû§Äܹ»´´½¨¡¢´æ´¢ºÍ¹²ÏíÎĵµ¡¢»ã±¨µÈ¶àÖÖÀàÐ͵ÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖȨÏÞÖÎÀíºÍ°²È«½ÚÔì¡£¡£¡£¡£¡£¡£¡£Ëü¿ÉÓëÆäËûMicrosoft 365¹¤¾ß£¨ÈçOutlook¡¢TeamsºÍOneDrive£©¼¯³É£¬£¬£¬£¬£¬£¬£¬£¬¿í·ºÀûÓÃÓÚ×éÖ¯ÄڵĺÏ×÷ºÍÐÅÏ¢ÖÎÀí¡£¡£¡£¡£¡£¡£¡£
2025Äê7ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Microsoft SharePointÖеÄÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-53770£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚSharePoint´¦ÖÃHTTP RefererͷʱµÄȱµã£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÈÏÖ¤Ö´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£·ì϶½áºÏÁËCVE-2025-49706ºÍCVE-2025-49704£¬£¬£¬£¬£¬£¬£¬£¬ÐγÉÃûΪToolShellµÄ¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃSharePointµÄ·´ÐòÁл¯·ì϶ִÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÌáÈ¡SharePoint·þÎñÆ÷µÄÃÜÔ¿×ÊÁÏ£¨ÈçValidationKeyºÍDecryptionKey£©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÌìÉúÓÐЧµÄ¹¥»÷ÔØºÉ£¨Èç__VIEWSTATE£©£¬£¬£¬£¬£¬£¬£¬£¬½øÒ»²½½ÚÔì·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬»ñµÃ³ÖÐø½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶Òѱ»¿í·ºÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¶à¸öSharePoint·þÎñÆ÷ÔÚ2025Äê7ÔÂ18ÈÕ±»¹¥Ï£¬£¬£¬£¬£¬£¬£¬£¬·ì϶ÆÀ·Ö9.8·Ö£¬£¬£¬£¬£¬£¬£¬£¬·ì϶¼¶±ðÑϳÁ¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ