Remote Code Execution Vulnerability in Microsoft SharePoint Server
CVE-2025-21344
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 14 January 2025
Summary
A vulnerability in Microsoft SharePoint Server allows remote attackers to execute arbitrary code on vulnerable installations. This can occur if an attacker sends a specially crafted request to the target server. The flaw could lead to unauthorized access and manipulation of sensitive data. It is imperative for organizations to apply the necessary patches and implement security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5483.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10416.20041
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.17928.20356
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved