[CVE-2025-49704] ToolShell - A Critical SharePoint Vulnerability Chain under Active Exploitation
blog.viettelcybersecurity.com | research | CVE-2025-49704 | #rce
Summary
I. EXECUTIVE SUMMARYIn July 2025, Viettel Threat Intelligence observed an actively exploited chain of critical vulnerabilities targeting Microsoft SharePoint systems, commonly referred to as the ToolShell vulnerability chain. This chain consists of the following four vulnerabilities: - CVE-2025-49704: A deserialization vulnerability in DataSetSurrogateSelector that allows remote code execution when processing
- Published
- Collected
Skip to content