Junglewise Threat Intelligence

CVE-2025-49704: Microsoft SharePoint code injection vulnerability

CVE-2025-49704 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-07-22

Technologies: Microsoft SharePoint Server 2019, Microsoft SharePoint Server 2016 Enterprise Edition, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used collaboration and document management platform, contains a vulnerability that allows attackers to run unauthorized code on the server. An attacker with basic user permissions can exploit this flaw to take control of the system, potentially leading to data theft or service disruption. This vulnerability has been observed being used in active attacks, making immediate patching or decommissioning of older versions critical.

Technical details

A code injection vulnerability (CWE-94) exists in Microsoft SharePoint Server due to improper control of code generation. An attacker with low-privileged 'Authorized' access can exploit this over the network without user interaction to achieve remote code execution (RCE). The vulnerability is known to be exploited in the wild and can be chained with CVE-2025-49706. Notably, a patch bypass (CVE-2025-53770) was later identified, requiring administrators to apply the most recent cumulative updates to ensure full remediation. Affected versions include SharePoint Server 2016 and 2019, while EOL versions like 2013 remain permanently vulnerable.

Affected products

  • Microsoft SharePoint Server 2016 Enterprise Edition
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server 2013 End of Life

Timeline

  • 2025-07-08: disclosed: Initial disclosure by Microsoft
  • 2025-07-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-07-22: advisory: Microsoft blog post regarding active exploitation published

Related threats