PT-2025-28601 · Microsoft · Sharepoint Server

Trend Zero Day Initiative

+1

·

Published

2025-07-08

·

Updated

2025-09-12

·

CVE-2025-49704

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions:**

Microsoft SharePoint versions prior to the July 2025 patchday

Microsoft SharePoint Server 2016

Microsoft SharePoint Server 2019

Microsoft SharePoint Server Subscription Edition (SE)

Microsoft Office SharePoint (affected versions not specified)

**Description:**

A code injection vulnerability exists in Microsoft SharePoint, allowing an authenticated attacker to execute arbitrary code over a network. This vulnerability is related to improper control of code generation and deserialization of untrusted data. The vulnerability has been actively exploited by multiple actors, including those attributed to Chinese state-sponsored groups, resulting in breaches of US federal agencies. Approximately 24.9k services are found to be affected yearly. The initial patch released by Microsoft for CVE-2025-49704 was ineffective, and attackers were able to bypass it. The vulnerability allows for remote code execution and potential deployment of web shells. Exploitation can lead to unauthorized access and data breaches.

**Recommendations:**

For Microsoft SharePoint Server 2016, install the latest patches.

For Microsoft SharePoint Server 2019, install the latest patches.

For Microsoft SharePoint Server Subscription Edition (SE), install the latest patches.

For all affected versions, apply the July 2025 security updates.

For systems where the initial patch was applied, ensure configuration upgrades are manually run to fully address the vulnerability.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08436
CVE-2025-49704
ZDI-25-581

Affected Products

Sharepoint Server