CVE-2025-21348
published 2025-01-14CVE-2025-21348: Microsoft SharePoint Server Remote Code Execution Vulnerability
PriorityP347high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.77%
75.8th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5483.1001 | 16.0.5483.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10416.20041 | 16.0.10416.20041 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.17928.20356 | 16.0.17928.20356 |
| microsoft | sharepoint_server | < 16.0.17928.20356 | 16.0.17928.20356 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hgf-cx4c-6c53: Microsoft SharePoint Server Remote Code Execution Vulnerability
ghsa_unreviewed·2025-01-14
CVE-2025-21348 [HIGH] CWE-285 GHSA-4hgf-cx4c-6c53: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2025-01-14·CVSS 7.2
CVE-2025-21348 [HIGH] CWE-285 Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
FAQ: There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?
Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
An authenticated attacker with Site Owner permissions can use the vulnerability to inject arbitrary code and execute this code in the context of SharePoint Server.
FAQ: How could an attacker exploit the vulnerability?
An authenticated attacker with Site Owner permissions or higher cou
No detection rules found.
No public exploits indexed.
2025-01-14
Published