cbcvebase.
CVE-2025-21400
published 2025-02-11

CVE-2025-21400: Microsoft SharePoint Server Remote Code Execution Vulnerability

PriorityP261high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
29.34%
98.0th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5487.100016.0.5487.1000
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10416.2005016.0.10416.20050
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.17928.2039616.0.17928.20396
microsoftsharepoint_server< 16.0.17928.2039616.0.17928.20396
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker must be authenticated as at least a Site Owner on the SharePoint Server to exploit this RCE vulnerability via arbitrary code injection.
  • The attack vector is network-based and requires user interaction (UI:R); monitor for clients connecting to malicious/unexpected SharePoint servers, as the attacker can gain code execution on the connecting client.
  • ·Exploitation is rated 'More Likely' for the latest software release, though as of advisory publication it has not yet been publicly disclosed or actively exploited. Prioritize patching accordingly.

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.