Loading HuntDB...

CVE-2025-49704

HIGH
Published 2025-07-08T16:58:05.908Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-49704. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
8.8
/10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
Not Available
Attack Complexity
Not Available
Privileges Required
Not Available
User Interaction
Not Available
Scope
Not Available

Impact Metrics

Confidentiality
Not Available
Integrity
Not Available
Availability
Not Available

Description

No description available

Available Exploits

No exploits available for this CVE.

Related News

Disrupting active exploitation of on-premises SharePoint vulnerabilities

On July 19, 2025, Microsoft Security Response Center (MSRC) published a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. The…

Biztoc.com 2025-07-23 05:38
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on July 22, 2025, added two Microsoft SharePoint flaws, CVE-2025-49704 and CVE-2025-49706, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. To tha…

Internet 2025-07-23 04:40
CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability CVE-2025-49706 Microsoft SharePoint Impro…

Cisa.gov 2025-07-22 12:00
菴処

2025 綛7 禹礇絅磧彜羂 (2025.07.10) d信罩c Sharepoint CVE-2025-49704 CVE-2025-49706 Pwn2Own ㏍сToolShell 違ToolShell 荐眼 CVE-2025-53770 CVE-2025-53771 違 Sharepoint (⒢ケ 紙с Customer guidance for SharePoint vulnerability CVE-2025-53770 (Microsoft, 2025.07.19…

Ryukoku.ac.jp 2025-07-21 15:00

Affected Products

Known Exploited Vulnerability

This vulnerability is actively being exploited in the wild

View KEV Details

Remediation Status

Overdue

Due Date

July 23, 2025

Added to KEV

July 22, 2025

Required Action

CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Affected Product

Vendor/Project: Microsoft
Product: SharePoint

Ransomware Risk

Known Ransomware Use
KEV Catalog Version: 2025.07.22 Released: July 22, 2025

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected Products (ENISA)

microsoft
microsoft sharepoint server 2019

ENISA Scoring

CVSS Score (3.1)

8.8
/10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

EPSS Score

0.300
probability

Data provided by ENISA EU Vulnerability Database. Last updated: July 22, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-mh5q-j7vq-g5g7

Advisory Details

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: July 8, 2025, Modified: July 22, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

22 posts
Reddit 10 hours, 59 minutes ago
technadu
Exploit

🚨 Multiple U.S. government agencies reportedly breached in major SharePoint vulnerability exploit, including the Department of Homeland Security, NIH, and possibly Qatari systems. 🚨 The U.S. Department of Homeland Security (DHS) is reportedly among the federal agencies compromised in the recent SharePoint exploit campaign. u/Microsoft has now confirmed the involvement …

Also mentions: CVE-2025-49706
1
1.0
View Original High Risk
Reddit 14 hours, 37 minutes ago
Sunitha_Sundar_5980
Exploit

Critical Zero-Day in Microsoft SharePoint Enables Unauthenticated Remote Code Execution CVE-2025-53770 (CVSS 9.8) is a critical zero-day vulnerability affecting **on-premises Microsoft SharePoint Server**. It is a variant of CVE-2025-49704 and stems from unsafe deserialization of untrusted data, allowing **unauthenticated remote code execution** over the network. Attackers exploit this flaw to …

1
1.0
View Original High Risk
Reddit 17 hours, 50 minutes ago
crstux
Exploit

🔥 Top 10 Trending CVEs (24/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2024-4947](https://nvd.nist.gov/vuln/detail/CVE-2024-4947)** - 📝 Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security …

1
1.0
View Original High Risk
Reddit 1 day, 16 hours ago
Leonie-Lionheard
Exploit

Microsoft bleibt stabil - diesmal Sharepoint > CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks > CVE-2025-49704 – SharePoint Remote Code Execution CVE-2025-49706 – SharePoint Post-auth Remote Code Execution CVE-2025-53770 – SharePoint ToolShell Authentication Bypass and Remote Code Execution CVE-2025-53771 – SharePoint ToolShell Path Traversal

9
9.0
View Original High Risk
Reddit 1 day, 17 hours ago
technadu
Exploit

Alert: ⚠️ NNSA Breached via SharePoint Zero-Days—Nation-State Attack Suspected The U.S. National Nuclear Security Administration was reportedly compromised using chained SharePoint vulnerabilities CVE-2025-49706 and CVE-2025-49704. 🔹 Exploited servers were on-prem 🔹 No classified data accessed, but dozens of servers impacted 🔹 Patches released; CISA added flaws tothe KEV list 🔗 …

Also mentions: CVE-2025-49706
1
1.0
View Original High Risk
Reddit 1 day, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (23/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-49113](https://nvd.nist.gov/vuln/detail/CVE-2025-49113)** - 📝 Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading …

2
2.0
View Original High Risk
Reddit 2 days, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (22/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53816](https://nvd.nist.gov/vuln/detail/CVE-2025-53816)** - 📝 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in …

2
2.0
View Original High Risk
Reddit 2 days, 19 hours ago
Huge_Line4009
Exploit Payload

The "ToolShell" Zero-Day: How a Botched Patch Led to a Global SharePoint Meltdown In the world of cybersecurity, there are mistakes, and then there are **catastrophes**. In July 2025, we witnessed the latter. A botched patch for a critical vulnerability in Microsoft SharePoint Server didn't just fail to fix the …

2
2.0
View Original High Risk
Reddit 3 days, 12 hours ago
SolidBE

Security Updates Sharepoint, Netscaler en Cisco ISE **Ernstig beveiligingslek in Microsoft SharePoint wordt misbruikt** Het Nationaal Cyber Security Centrum (NCSC), Microsoft en het Amerikaanse cyberagentschap CISA slaan alarm: er wordt actief misbruik gemaakt van een kritieke kwetsbaarheid in Microsoft SharePoint. Dit lek, aangeduid als CVE-2025-53770, stelt aanvallers in staat om …

Reddit 3 days, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (21/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53771](https://nvd.nist.gov/vuln/detail/CVE-2025-53771)** - 📝 Microsoft SharePoint Server Spoofing Vulnerability - 📅 **Published:** 20/07/2025 - 📈 **CVSS:** 6.3 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C - 📣 **Mentions:** 9 - 📝 **Analysis:** A SharePoint Server spoofing …

1
1.0
View Original High Risk

References

Published: 2025-07-08T16:58:05.908Z
Last Modified: 2025-07-22T15:38:18.308Z
Copied to clipboard!