CVE-2025-49704
8.8Microsoft · SharePoint
A code injection vulnerability in Microsoft SharePoint allows an authenticated attacker to execute arbitrary code over a network.
Executive summary
A critical code injection vulnerability in Microsoft SharePoint Server allows authenticated attackers to execute arbitrary code, and it is currently being exploited in the wild.
Vulnerability
This vulnerability, classified as CWE-94, involves improper control of code generation within the SharePoint environment. An attacker with authenticated access can leverage this flaw to perform unauthorized code execution over the network.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve total system compromise, potentially leading to unauthorized data access, modification, or complete denial of service. Given the CVSS score of 8.8 and the confirmed active exploitation in the wild, this poses a severe risk to organizational operations and data integrity.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official security update guide immediately to patch the vulnerable SharePoint instances.
Proactive Monitoring: Review SharePoint server logs for unusual administrative activity or unexpected process spawns that deviate from baseline operational patterns.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block malicious injection attempts targeting the SharePoint application layer while pending patch deployment.
Exploitation status
Public Exploit Available: Yes, a Metasploit module is available.
Analyst recommendation
Due to the confirmed active exploitation and the high severity of the impact, immediate patching is required. Organizations must prioritize the deployment of the vendor-supplied updates to all affected SharePoint servers to prevent potential compromise and ensure the security of the internal network.
More Microsoft CVEs
Sources
- Microsoft SharePoint Remote Code Execution Vulnerability Vendor advisory