Remote Code Execution Vulnerability in Microsoft SharePoint Server
CVE-2025-30384

7.4HIGH

What is CVE-2025-30384?

A security vulnerability exists in Microsoft SharePoint Server that permits an unauthorized attacker to exploit deserialization of untrusted data. This exploitation may lead to the execution of arbitrary code on the affected system, compromising its integrity and potentially leading to data breaches. Organizations using vulnerable versions of SharePoint Server should implement mitigations and promptly apply updates to safeguard their systems.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5500.1001

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20010

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.18526.20286

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30384 : Remote Code Execution Vulnerability in Microsoft SharePoint Server