PT-2025-28601 · Microsoft · Sharepoint Server
Trend Zero Day Initiative
+1
·
Published
2025-07-08
·
Updated
2025-10-30
·
CVE-2025-49704
CVSS v2.0
9.0
  9.0
High
| Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C | 
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint versions prior to July 2025 patchday
Microsoft SharePoint Server 2016
Microsoft SharePoint Server 2019
Microsoft SharePoint Server Subscription Edition (SE)
Microsoft SharePoint (affected versions not specified)
Description
Microsoft SharePoint contains a flaw related to improper control of code generation, specifically a code injection issue. This allows an authorized attacker to execute code over a network. The vulnerability is related to deserialization of untrusted data and can be exploited through specially crafted WebPart POST requests. Exploitation has been observed in real-world attacks, including targeting US federal agencies like the Kansas City National Security Campus (KCNSC), and is actively exploited by multiple actors, including groups attributed to China. Initial patches released by Microsoft were found to be ineffective, requiring further updates and configuration upgrades. The vulnerability allows attackers to bypass authentication and gain remote code execution, potentially enabling shell access, database queries, and web shell deployment. The vulnerability is also a bypass of a previously patched issue. Approximately 24.9K services are found to be vulnerable yearly.
Recommendations
For all affected versions of Microsoft SharePoint, install the latest security patches released by Microsoft.
For SharePoint Server 2016, 2019, and Subscription Edition, ensure the latest patches are installed to resolve CVE-2025-49704.
Manually run configuration upgrades after applying the patches, as this step was often missed and left systems vulnerable.
Fix
RCE
Code Injection
 Found an issue in the description?  Have something to add?  Feel free to write us 👾 
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-08436
CVE-2025-49704
ZDI-25-581
Affected Products
Sharepoint Server
References · 216
- https://microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities · Vendor Advisory
- https://zerodayinitiative.com/advisories/ZDI-25-581 · Security Note
- https://bdu.fstec.ru/vul/2025-08436 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49704 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49704 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-49704 · Security Note
- https://t.me/aptreports/20984 · Telegram Post
- https://twitter.com/grok/status/1948380461438558521 · Twitter Post
- https://twitter.com/CTI131/status/1958498892661801000 · Twitter Post
- https://twitter.com/DarkAtlasSquad/status/1946931832013881706 · Twitter Post
- https://twitter.com/shah_sheikh/status/1947882514732785726 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1o6670r/top_10_trending_cves_14102025 · Reddit Post
- https://twitter.com/fridaysecurity/status/1947846953590518101 · Twitter Post
- https://t.me/aptreports/20962 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1m0ds56/top_10_trending_cves_15072025 · Reddit Post