CVE-2025-54897
published 2025-09-09CVE-2025-54897: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
PriorityP266high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
13.60%
96.1th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5517.1000 | 16.0.5517.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20047 | 16.0.10417.20047 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19127.20100 | 16.0.19127.20100 |
| microsoft | sharepoint_server | < 16.0.19127.20100 | 16.0.19127.20100 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploitable by any authenticated (low-privilege) network user via deserialization of untrusted data in Microsoft SharePoint — monitor for unexpected deserialization activity or anomalous SharePoint HTTP requests from authenticated low-privilege accounts. ↗
- →Attack requires no elevated privileges (PR:L) and no prior system knowledge (AC:L), meaning any authenticated user can achieve repeatable exploitation — baseline and alert on unusual SharePoint API calls or POST requests from standard user accounts. ↗
- →Exploitation is remotely exploitable from the internet (AV:N, AC:L) with repeatable success — consider perimeter-level inspection of SharePoint-bound traffic and enforce network segmentation to limit external access to SharePoint endpoints. ↗
- ·SharePoint Server 2016 and SharePoint Enterprise Server 2016 share the same KB update number — ensure both product variants are patched under the same KB to be protected. ↗
- ·As of advisory publication, the vulnerability has not been publicly disclosed or actively exploited, but Microsoft rates exploitation as 'Less Likely' — prioritize patching accordingly. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2025-09-09·CVSS 8.8
CVE-2025-54897 [HIGH] CWE-502 Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?
Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.
FAQ: According to the
GHSA
GHSA-rvp7-398f-7v5c: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-09-09
CVE-2025-54897 [HIGH] CWE-502 GHSA-rvp7-398f-7v5c: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
Securelist
From cheats to exploits: Webrat spreading via GitHub
blogs_securelist·2025-12-23·CVSS 9.8
[CRITICAL] From cheats to exploits: Webrat spreading via GitHub
Table of Contents
Distribution and the malicious sample
Campaign objectives
Conclusion
Indicators of compromise
Authors
Maxim Starodubov
In early 2025, security researchers uncovered a new malware family named Webrat. Initially, the Trojan targeted regular users by disguising itself as cheats for popular games like Rust, Counter-Strike, and Roblox, or as cracked software. In September, the attackers decided to widen their net: alongside gamers and users of pirated software, they are now targeting inexperienced professionals and students in the information security field.
## Distribution and the malicious sample
In October, we uncovered a campaign that had been distributing Webrat via GitHub repositories since at least September. To lure in victims, the attackers leveraged vulnerab
Securelist
Webrat, disguised as exploits, is spreading via GitHub repositories
blogs_securelist·2025-12-23·CVSS 9.8
[CRITICAL] Webrat, disguised as exploits, is spreading via GitHub repositories
Table of Contents
- Distribution and the malicious sample
- Campaign objectives
- Conclusion
- Indicators of compromise
Authors
- Maxim Starodubov
In early 2025, security researchers uncovered a new malware family named Webrat. Initially, the Trojan targeted regular users by disguising itself as cheats for popular games like Rust, Counter-Strike, and Roblox, or as cracked software. In September, the attackers decided to widen their net: alongside gamers and users of pirated software, they are now targeting inexperienced professionals and students in the information security field.
## Distribution and the malicious sample
In October, we uncovered a campaign that had been distributing Webrat via GitHub repositories since at least September. To lure in victims, the attackers leveraged
Bleepingcomputer
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
blogs_bleepingcomputer·2025-09-09·CVSS 8.8
[HIGH] Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
## Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
## Lawrence Abrams
41 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
22 Remote Code Execution Vulnerabilities
16 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
1 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released on Patch Tuesday.
Therefore, the number of flaws does not include three Azure, one Dynamics 365 FastTrack Implementation Assets, two Mariner, five Microsoft Edge, and 1 Xbox vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5065426 & KB5065431 cumulative updat
Tenable
September 2025 Microsoft Patch Tuesday | Tenable®
blogs_tenable·2025-09-09
September 2025 Microsoft Patch Tuesday | Tenable®
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2025-09-09
Published