非影资讯
面向安全从业者的中英双语安全研究与漏洞情报精选。

[CVE-2025-49704] ToolShell - A Critical SharePoint Vulnerability Chain under Active Exploitation

blog.viettelcybersecurity.com | 研究 | CVE-2025-49704 | #rce

摘要

I. EXECUTIVE SUMMARYIn July 2025, Viettel Threat Intelligence observed an actively exploited chain of critical vulnerabilities targeting Microsoft SharePoint systems, commonly referred to as the ToolShell vulnerability chain. This chain consists of the following four vulnerabilities: - CVE-2025-49704: A deserialization vulnerability in DataSetSurrogateSelector that allows remote code execution when processing
发布时间
收录时间

原文 ↗

相关内容

返回