Executive brief
Microsoft SharePoint, a widely used platform for document management and collaboration, contains a security flaw that allows unauthorized individuals to impersonate legitimate users or services. An attacker can exploit this to view sensitive internal documents and make unauthorized changes to information. This vulnerability has been observed being used in active attacks, making immediate patching or disconnection of older, unsupported versions critical for protecting corporate data.
Technical details
An improper authentication vulnerability (CWE-287) exists in Microsoft SharePoint Server. The flaw allows an unauthenticated attacker to perform network-based spoofing, potentially leading to the disclosure of sensitive information and unauthorized data modification. The vulnerability is notable for being actively exploited in the wild and can be chained with other vulnerabilities like CVE-2025-49704. While Microsoft initially assigned a Medium severity CVSS score of 6.5, the vulnerability is categorized as Critical due to active exploitation. A patch bypass was later identified as CVE-2025-53771, requiring the latest updates for full remediation. Affected versions include SharePoint Enterprise Server 2016, 2019, and Subscription Edition.
Affected products
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition before 16.0.18526.20424
Timeline
- 2025-07-16: disclosed: Initial NIST analysis and CPE assignment
- 2025-07-22: advisory: Microsoft and CISA published advisories regarding active exploitation
- 2025-07-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog