¡¾Îó²îͨ¸æ¡¿Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-53770)
Ðû²¼Ê±¼ä 2025-07-21Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-53770 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-07-21 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Microsoft SharePointÊÇÒ»¿îÆóÒµ¼¶Ð×÷ƽ̨£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔö½øÐÅÏ¢¹²Ïí¡¢ÄÚÈÝÖÎÀíºÍÍŶÓÐ×÷¡£¡£¡£¡£¡£ËüÖ§³ÖÎĵµÖÎÀí¡¢ÄÚÈÝÐû²¼¡¢Êý¾Ý¹²ÏíºÍÄÚ²¿ÍøÕ¾½¨Éè¡£¡£¡£¡£¡£SharePointÌṩÁËǿʢµÄÊÂÇéÁ÷¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§ÖÎÀíÏîÄ¿¡¢Ê¹ÃüºÍÊÂÇéÁ÷£¬£¬£¬£¬£¬£¬£¬ÌáÉýÍŶÓЧÂÊ¡£¡£¡£¡£¡£Óû§¿ÉÒÔ½¨Éè¡¢´æ´¢ºÍ¹²ÏíÎĵµ¡¢±¨¸æµÈ¶àÖÖÀàÐ͵ÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖȨÏÞÖÎÀíºÍÇå¾²¿ØÖÆ¡£¡£¡£¡£¡£Ëü¿ÉÓëÆäËûMicrosoft 365¹¤¾ß£¨ÈçOutlook¡¢TeamsºÍOneDrive£©¼¯³É£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ×éÖ¯ÄÚµÄÐ×÷ºÍÐÅÏ¢ÖÎÀí¡£¡£¡£¡£¡£
2025Äê7ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Microsoft SharePointÖеÄÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-53770£©¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚSharePoint´¦Öóͷ£HTTP RefererͷʱµÄȱÏÝ£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬Î´¾ÈÏÖ¤Ö´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£Îó²îÁ¬ÏµÁËCVE-2025-49706ºÍCVE-2025-49704£¬£¬£¬£¬£¬£¬£¬ÐγÉÃûΪToolShellµÄ¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃSharePointµÄ·´ÐòÁл¯Îó²îÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÌáÈ¡SharePointЧÀÍÆ÷µÄÃÜÔ¿ÖÊÁÏ£¨ÈçValidationKeyºÍDecryptionKey£©£¬£¬£¬£¬£¬£¬£¬Äܹ»ÌìÉúÓÐÓõĹ¥»÷ÔØºÉ£¨Èç__VIEWSTATE£©£¬£¬£¬£¬£¬£¬£¬½øÒ»²½¿ØÖÆÐ§ÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬»ñµÃÒ»Á¬»á¼ûȨÏÞ¡£¡£¡£¡£¡£´ËÎó²îÒѱ»ÆÕ±éʹÓ㬣¬£¬£¬£¬£¬£¬¶à¸öSharePointЧÀÍÆ÷ÔÚ2025Äê7ÔÂ18ÈÕ±»¹¥ÏÝ£¬£¬£¬£¬£¬£¬£¬Îó²îÆÀ·Ö9.8·Ö£¬£¬£¬£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ