PT-2025-28601 · Microsoft · Sharepoint Server
Trend Zero Day Initiative
+1
·
Published
2025-07-08
·
Updated
2025-09-12
·
CVE-2025-49704
9.0
High
Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Microsoft SharePoint versions prior to the July 2025 patchday
Microsoft SharePoint Server 2016
Microsoft SharePoint Server 2019
Microsoft SharePoint Server Subscription Edition (SE)
Microsoft Office SharePoint (affected versions not specified)
**Description:**
A code injection vulnerability exists in Microsoft SharePoint, allowing an authenticated attacker to execute arbitrary code over a network. This vulnerability is related to improper control of code generation and deserialization of untrusted data. The vulnerability has been actively exploited by multiple actors, including those attributed to Chinese state-sponsored groups, resulting in breaches of US federal agencies. Approximately 24.9k services are found to be affected yearly. The initial patch released by Microsoft for CVE-2025-49704 was ineffective, and attackers were able to bypass it. The vulnerability allows for remote code execution and potential deployment of web shells. Exploitation can lead to unauthorized access and data breaches.
**Recommendations:**
For Microsoft SharePoint Server 2016, install the latest patches.
For Microsoft SharePoint Server 2019, install the latest patches.
For Microsoft SharePoint Server Subscription Edition (SE), install the latest patches.
For all affected versions, apply the July 2025 security updates.
For systems where the initial patch was applied, ensure configuration upgrades are manually run to fully address the vulnerability.
Fix
RCE
Code Injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 200
- https://bdu.fstec.ru/vul/2025-08436 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49704 · Vendor Advisory
- https://microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities · Vendor Advisory
- https://zerodayinitiative.com/advisories/ZDI-25-581 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-49704 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49704 · Security Note
- https://twitter.com/kaspersky/status/1948683669440491733 · Twitter Post
- https://twitter.com/gothburz/status/1947165167319425378 · Twitter Post
- https://twitter.com/grok/status/1948058443123974443 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1mh9d03/top_10_trending_cves_04082025 · Reddit Post
- https://twitter.com/0x534c/status/1946791814222242107 · Twitter Post
- https://twitter.com/CTI131/status/1958498892661801000 · Twitter Post
- https://twitter.com/TechNadu/status/1948421204513030213 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1m6a2hn/top_10_trending_cves_22072025 · Reddit Post
- https://t.me/aptreports/20771 · Telegram Post