CVE-2025-64672

8.8

Microsoft · SharePoint Server Subscription Edition

A cross-site scripting vulnerability in Microsoft SharePoint Server Subscription Edition allows an authorized attacker to perform spoofing over a network.

Executive summary

A high-severity cross-site scripting vulnerability in Microsoft SharePoint Server Subscription Edition allows authenticated attackers to perform network-based spoofing attacks.

Vulnerability

This vulnerability is a cross-site scripting (CWE-79) flaw caused by improper neutralization of input during web page generation. An attacker with authorized access can exploit this to execute malicious scripts and achieve spoofing within the context of the affected SharePoint environment.

Business impact

The potential for spoofing attacks poses a significant risk to organizational integrity and user trust. Because the vulnerability allows for unauthorized script execution, an attacker could manipulate page content or hijack user sessions, leading to data compromise or unauthorized actions. With a CVSS score of 8.8, this flaw represents a high-risk entry point for lateral movement or information theft within the corporate network.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to version 16.0.19127.20378 or later as specified in the Microsoft Security Update Guide.

Proactive Monitoring: Review web server and application access logs for unusual patterns, such as unexpected script tags or encoded characters being submitted to SharePoint endpoints.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to inspect incoming traffic and block common cross-site scripting payloads targeting SharePoint environments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high severity of this vulnerability necessitates prompt attention from IT and security teams. Administrators should prioritize the deployment of the provided security update to eliminate the underlying input validation flaw and prevent potential spoofing attacks. Failure to patch may expose the organization to elevated risks of data manipulation or unauthorized interaction within the SharePoint environment.

More Microsoft CVEs

Sources