vulnerability

Microsoft SharePoint: CVE-2025-49704: Microsoft SharePoint Remote Code Execution Vulnerability

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Jul 8, 2025
Added
Jul 8, 2025
Modified
Sep 9, 2025

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Solutions

microsoft-sharepoint-sharepoint_2016-kb5002744microsoft-sharepoint-sharepoint_2019-kb5002741
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.