Remote Code Execution Vulnerability in Microsoft Office SharePoint
CVE-2025-30382
7.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-30382?
A vulnerability in Microsoft Office SharePoint allows attackers to exploit improper deserialization of untrusted data, enabling unauthorized execution of code. This flaw could lead to the compromise of sensitive information and disruption of services, underscoring the importance of timely updates and security patches.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5500.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20010
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.18526.20286
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved