cbcvebase.
CVE-2025-49701
published 2025-07-08

CVE-2025-49701: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PriorityP259high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.83%
53.6th percentile
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5508.100016.0.5508.1000
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2002716.0.10417.20027
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.18526.2042416.0.18526.20424
microsoftsharepoint_server< 16.0.18526.2042416.0.18526.20424
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability requires attacker to be authenticated as at least a Site Owner on the SharePoint Server to exploit; monitor for unusual code execution or file writes initiated by Site Owner-level accounts on SharePoint.
  • The attack is network-based and remotely exploitable from the internet with low complexity; monitor SharePoint Server for anomalous inbound network requests from authenticated low-privilege users attempting remote code execution.
  • Any authenticated user (not just admins) can trigger this vulnerability; broaden monitoring scope to all authenticated SharePoint users, not just privileged accounts.
  • ·Exploitation is rated 'More Likely' by Microsoft for the latest software release, despite no confirmed in-the-wild exploitation at time of publication; prioritize patching accordingly.
  • ·The vulnerability is an improper authorization flaw, not a missing-authentication flaw; access controls alone (e.g., blocking anonymous access) are insufficient mitigation since any authenticated user can be an attacker.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.