CVE-2025-47166
published 2025-06-10CVE-2025-47166: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
PriorityP271high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
14.06%
96.2th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5504.1001 | 16.0.5504.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20018 | 16.0.10417.20018 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.18526.20396 | 16.0.18526.20396 |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | < 16.0.18526.20396 | 16.0.18526.20396 |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated or low-privileged NTLM authentication attempts against SharePoint Central Administration endpoints, particularly over unencrypted HTTP. ↗
- →Alert on access to the SharePoint `_api/web` endpoint by accounts with minimal permissions (Site Member or lower), especially when followed by bulk metadata retrieval. ↗
- →Detect repeated NTLM authentication failures against SharePoint endpoints that may indicate credential brute-forcing or enumeration using NTLM error codes as oracles. ↗
- →Flag network-based deserialization exploitation attempts against SharePoint Server from authenticated accounts with Site Member permissions (PR:L) that result in remote code execution. ↗
- ·The exploit PoC uses a PoC IP and port (10.10.0.15:10626) representative of a SharePoint Central Administration instance; real-world deployments may use different ports. ↗
- ·The vulnerability requires a minimum of Site Member permissions; fully anonymous or unauthenticated exploitation is not indicated by current disclosures. ↗
- ·As of the MSRC advisory, the exploit has not been observed in the wild and is rated 'Exploitation Less Likely'. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2025-06-10·CVSS 8.8
CVE-2025-47166 [HIGH] CWE-502 Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
FAQ: How could an attacker exploit the vulnerability?
In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=108208
Reference: https://support.microsoft.com/help/5002732
Refe
GHSA
GHSA-jvcx-4h9f-wx33: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-06-10
CVE-2025-47166 [HIGH] CWE-502 GHSA-jvcx-4h9f-wx33: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
No detection rules found.
2025-06-10
Published