Back Socprime CVE-2026-45659: SharePoint Deserialization Flaw Enables RCE
CVE-2026-45659 is a critical deserialization of untrusted data vulnerability affecting Microsoft SharePoint Server. An authenticated user with low-level Site Member privileges can exploit the flaw to achieve remote code execution (RCE) within the IIS application pool identity. The issue belongs to a broader class of SharePoint deserialization vulnerabilities that can ultimately lead to farm-wide compromise.
The investigation identifies a deserialization sink within the ASP.NET stack, likely involving handlers under _vti_bin/ , _api/ , or /_layouts/15/ . Researchers note that exploitation can rely on gadget chains such as ObjectDataProvider to trigger arbitrary command execution. The potential impact is increased by the elevated privileges typically assigned to the SharePoint application pool identity.
The primary mitigation is to apply the May 2026 SharePoint security updates, including KB5002863, KB5002870, or KB5002868, and verify patched builds through Central Administration. Previously exposed environments should also rotate the MachineKey to prevent continued exploitation through forged ViewState. For long-term risk reduction, organizations should consider migrating eligible workloads to SharePoint Online.
If anomalous child processes such as cmd.exe or powershell.exe are spawned by w3wp.exe , responders should immediately isolate the affected SharePoint front-end server. Incident response should include a full farm audit, MachineKey rotation, and investigation for potential webshells within SharePoint directories. Teams should also confirm that all farm components are fully updated by running psconfig.exe .
## Simulation Execution
Attack Narrative & Commands: The adversary has identified a deserialization flaw in a SharePoint instance. To mask their activity and leverage the identity of the IIS worker process, they attempt to execute w3wp.exe via a command prompt session. This is a “reverse” execution pattern often seen in sophisticated payload delivery where the attacker attempts to interact with the web service process directly to perform in-memory manipulation or to proxy commands through a trusted service identity. The goal is to trigger the rule’s detection of w3wp.exe being spawned by cmd.exe .
Attack Narrative & Commands: The adversary has identified a deserialization flaw in a SharePoint instance. To mask their activity and leverage the identity of the IIS worker process, they attempt to execute w3wp.exe via a command prompt session. This is a “reverse” execution pattern often seen in sophisticated payload delivery where the attacker attempts to interact with the web service process directly to perform in-memory manipulation or to proxy commands through a trusted service identity. The goal is to trigger the rule’s detection of w3wp.exe being spawned by cmd.exe .
Regression Test Script: # Simulation Script: Triggering anomalous w3wp.exe child process creation # This script mimics an attacker spawning w3wp.exe from a cmd.exe context. Write-Host "[+] Starting Simulation: Spawning w3wp.exe from cmd.exe" -ForegroundColor Cyan $w3wpPath = "C:WindowsSystem32inetsrvw3wp.exe" # Check if w3wp.exe exists to avoid script failure if (Test-Path $w3wpPath) { # Use cmd.exe to launch w3wp.exe. # Note: This will likely fail to actually run w3wp properly as it's a service, # but the PROCESS CREATION telemetry will be generated. Start-Process "cmd.exe" -ArgumentList "/c `"$w3wpPath`"" -WindowStyle Hidden Write-Host "[+] Command sent. Check Sysmon/Security logs for w3wp.exe child of cmd.exe" -ForegroundColor Green } else { Write-Host "[-] Error: w3wp.exe not found at $w3wpPath. Is IIS installed?" -ForegroundColor Red }
Regression Test Script:
Cleanup Commands: # Cleanup: No persistent files were created, but ensure any orphaned processes are closed. Stop-Process -Name "w3wp" -ErrorAction SilentlyContinue Stop-Process -Name "cmd" -ErrorAction SilentlyContinue Write-Host "[+] Cleanup complete." -ForegroundColor Cyan
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
