CVE-2025-59228
published 2025-10-14CVE-2025-59228: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.28%
67.0th percentile
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5522.1000 | 16.0.5522.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20059 | 16.0.10417.20059 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19127.20262 | 16.0.19127.20262 |
| microsoft | sharepoint_server | < 16.0.19127.20262 | 16.0.19127.20262 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is remotely exploitable over the network with low attack complexity; monitor for authenticated SharePoint requests from unexpected sources or unusual code execution patterns on SharePoint Server. ↗
- →Restrict and audit accounts with Site Member permissions (or higher) on SharePoint Server, as this is the minimum privilege level required to exploit the vulnerability. ↗
- ·SharePoint Server 2016 and SharePoint Enterprise Server 2016 share the same KB update number; both versions require the same security patch to be protected. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2025-10-14·CVSS 8.8
CVE-2025-59228 [HIGH] CWE-20 Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?
The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.
FAQ: I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I a
GHSA
GHSA-f8r8-qh8w-ggm2: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-10-14
CVE-2025-59228 [HIGH] CWE-20 GHSA-f8r8-qh8w-ggm2: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
2025-10-14
Published