Deserialization Vulnerability in Microsoft SharePoint
CVE-2025-49712
8.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2025-49712?
A deserialization vulnerability in Microsoft Office SharePoint allows an unauthenticated attacker with authorized access to leverage untrusted data, potentially enabling remote code execution over a network. This flaw underscores the significance of validating and sanitizing inputs to prevent unauthorized actions within affected systems.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5513.1002
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20041