CVE-2025-47163
published 2025-06-10CVE-2025-47163: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
11.51%
95.5th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5504.1001 | 16.0.5504.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20018 | 16.0.10417.20018 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.18526.20396 | 16.0.18526.20396 |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | < 16.0.18526.20396 | 16.0.18526.20396 |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability class is deserialization of untrusted data in Microsoft SharePoint Server, enabling RCE over the network by an authenticated attacker with at minimum Site Member permissions. ↗
- →Attacker must be authenticated and hold at least Site Member permissions (PR:L) to exploit this vulnerability remotely — monitor for unusual authenticated SharePoint requests from low-privileged accounts performing deserialization-triggering operations. ↗
- ·Exploit status is currently 'Exploitation Less Likely' and not yet publicly disclosed or observed in the wild as of the advisory date — prioritize patching but no active threat campaign confirmed yet. ↗
- ·Customer action (patching) is explicitly required; affected product is Microsoft SharePoint Server. Patches are referenced via KB articles 5002732, 5002729, and 5002736. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv5.5MEDIUM
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c4r7-vqgv-hxrw: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-06-10
CVE-2025-47163 [HIGH] CWE-502 GHSA-c4r7-vqgv-hxrw: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
OSV
linux-azure vulnerabilities
osv·2025-05-07·CVSS 5.5
linux-azure vulnerabilities
linux-azure vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Block layer subsystem;
- Character device driver;
- Hardware crypto device drivers;
- GPU drivers;
- Media drivers;
- Network drivers;
- SCSI subsystem;
- USB Gadget drivers;
- Framebuffer layer;
- Ceph distributed file system;
- File systems infrastructure;
- JFS file system;
- Network file system (NFS) client;
- NILFS2 file system;
- SMB network file system;
- Netfilter;
- CAN network layer;
- IPv6 networking;
- MAC80211 subsystem;
- Netlink;
- Network traffic control;
- SCTP protocol;
- TIPC protocol;
(CVE-2025-21971, CVE-2024-50237, CVE-2023-52927, CVE-2023-52458,
CVE-2021-47163
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2025-06-10·CVSS 8.8
CVE-2025-47163 [HIGH] CWE-502 Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
FAQ: How could an attacker exploit the vulnerability?
In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=108208
Reference: https://support.microsoft.com/help/5002732
Refe
No detection rules found.
No public exploits indexed.
2025-06-10
Published