PT-2025-28603 · Microsoft · Sharepoint Server

Published

2025-07-08

·

Updated

2026-06-21

·

CVE-2025-49706

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Server Subscription Edition (affected versions not specified) Microsoft SharePoint Foundation (affected versions not specified)
Description Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing attacks over a network. This issue involves an authentication bypass within the ToolPane. In July 2025, Chinese state-backed groups, including Linen Typhoon and Violet Typhoon, exploited this flaw to gain access to on-premises servers at approximately 100 to 400 organizations, potentially enabling the theft of files and other data from affected systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08524
CVE-2025-49706
ZDI-25-580

Affected Products

Sharepoint Server