CVE-2025-59237
published 2025-10-14CVE-2025-59237: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.30%
81.3th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5522.1000 | 16.0.5522.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20059 | 16.0.10417.20059 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19127.20262 | 16.0.19127.20262 |
| microsoft | sharepoint_server | < 16.0.19127.20262 | 16.0.19127.20262 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attacker must be authenticated as at least a Site Owner to exploit; monitor for unusual code injection or deserialization activity originating from authenticated SharePoint site owner accounts over the network. ↗
- →The vulnerability is triggered by any authenticated user (low privilege required), not just admins — broaden monitoring scope to all authenticated SharePoint users, not just privileged accounts. ↗
- →Attack vector is network-based deserialization of untrusted data in Microsoft Office SharePoint — inspect SharePoint HTTP request payloads for malformed or unexpected serialized objects. ↗
- ·SharePoint Server 2016 and SharePoint Enterprise Server 2016 share the same KB update number — ensure both product variants are patched under the same KB. ↗
- ·As of advisory publication, the vulnerability has not been publicly disclosed or exploited in the wild, but exploitation is assessed as 'Less Likely' — prioritize patching accordingly. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2025-10-14·CVSS 8.8
CVE-2025-59237 [HIGH] CWE-502 Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
FAQ: How could an attacker exploit the vulnerability?
In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.
FAQ: I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?
Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.
FAQ: According to the CVSS metr
GHSA
GHSA-jwmr-xpm8-p7v6: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-10-14
CVE-2025-59237 [HIGH] CWE-502 GHSA-jwmr-xpm8-p7v6: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
2025-10-14
Published