Remote Code Execution Risk in Microsoft SharePoint by Microsoft
CVE-2025-30378
7HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-30378?
A vulnerability in Microsoft SharePoint arises from deserialization of untrusted data, permitting unauthorized attackers to execute code locally within the application. This flaw poses significant risks to data integrity and application security, highlighting the importance of stringent validation mechanisms for input data.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5500.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20010
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.18526.20286
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved