vulnerability

Microsoft SharePoint: CVE-2025-47172: Microsoft SharePoint Server Remote Code Execution Vulnerability

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Jun 10, 2025
Added
Jun 10, 2025
Modified
Sep 9, 2025

Description

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Solutions

microsoft-sharepoint-sharepoint_2016-kb5002732microsoft-sharepoint-sharepoint_2019-kb5002729microsoft-sharepoint-sharepoint_server_subscription_edition-kb5002736microsoft-sharepoint-sharepoint_subscription_edition-kb5002736
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.