Remote Code Execution Risk in Microsoft SharePoint by Microsoft
CVE-2025-30378

7HIGH

What is CVE-2025-30378?

A vulnerability in Microsoft SharePoint arises from deserialization of untrusted data, permitting unauthorized attackers to execute code locally within the application. This flaw poses significant risks to data integrity and application security, highlighting the importance of stringent validation mechanisms for input data.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5500.1001

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20010

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.18526.20286

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30378 : Remote Code Execution Risk in Microsoft SharePoint by Microsoft