Deserialization Vulnerability in Microsoft SharePoint Server
CVE-2025-53770

9.8CRITICAL

What is CVE-2025-53770?

A deserialization vulnerability in on-premises Microsoft SharePoint Server can be exploited by unauthorized attackers, allowing them to execute arbitrary code over a network. Microsoft is aware of exploits being used in the wild and is actively working on a comprehensive update to address this security concern. Users are advised to implement the mitigations specified in the official documentation to protect against potential exploitation.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems

Microsoft SharePoint Server 2019 x64-based Systems

Microsoft SharePoint Server Subscription Edition x64-based Systems

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53770 : Deserialization Vulnerability in Microsoft SharePoint Server