Executive brief
Microsoft SharePoint Server, a widely used platform for document management and collaboration, contains a critical security flaw that allows unauthorized attackers to take control of the server. By sending malicious data over the network, an attacker can execute arbitrary commands, potentially leading to the theft of sensitive corporate data, service outages, or a foothold for further attacks within the organization. This vulnerability is currently being exploited in the wild, and organizations are advised to apply mitigations immediately as a full patch may not yet be available for all versions.
Technical details
This vulnerability (CVE-2025-53770) is a deserialization of untrusted data flaw (CWE-502) in on-premises Microsoft SharePoint Server. It functions as a patch bypass for a previous vulnerability (CVE-2025-49704) and can be chained with other vulnerabilities like CVE-2025-53771 for full system compromise. An unauthenticated attacker can exploit this over the network without user interaction to achieve remote code execution (RCE). The vulnerability is actively exploited in the wild. Recommended mitigations include enabling Antimalware Scan Interface (AMSI) integration, deploying Defender AV, and disconnecting end-of-life versions (such as SharePoint 2013) from the internet.
Affected products
- Microsoft SharePoint Server On-premises versions (including 2013 and later)
Timeline
- 2025-07-20: disclosed
- 2025-07-20: advisory: Microsoft and CISA released guidance on exploitation
- 2025-07-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-07-20: exploited: Confirmed active exploitation in the wild