Loading HuntDB...

CVE-2025-49704

HIGH
Published 2025-07-08T16:58:05.908Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-49704. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
8.8
/10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
Not Available
Attack Complexity
Not Available
Privileges Required
Not Available
User Interaction
Not Available
Scope
Not Available

Impact Metrics

Confidentiality
Not Available
Integrity
Not Available
Availability
Not Available

Description

No description available

Available Exploits

No exploits available for this CVE.

Related News

CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities

CISA published a Malware Analysis Report (MAR) with analysis and associated detection signatures on files related to Microsoft SharePoint vulnerabilities: CVE-2025-49704 [CWE-94: Code Injection], CVE-2025-49706 [CWE-287: Improper Authenticat…

Cisa.gov 2025-08-06 12:00
Disrupting active exploitation of on-premises SharePoint vulnerabilities

On July 19, 2025, Microsoft Security Response Center (MSRC) published a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. The…

Biztoc.com 2025-07-23 05:38
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on July 22, 2025, added two Microsoft SharePoint flaws, CVE-2025-49704 and CVE-2025-49706, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. To tha…

Internet 2025-07-23 04:40
CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability CVE-2025-49706 Microsoft SharePoint Impro…

Cisa.gov 2025-07-22 12:00
菴処

2025 綛7 禹礇絅磧彜羂 (2025.07.10) d信罩c Sharepoint CVE-2025-49704 CVE-2025-49706 Pwn2Own ㏍сToolShell 違ToolShell 荐眼 CVE-2025-53770 CVE-2025-53771 違 Sharepoint (⒢ケ 紙с Customer guidance for SharePoint vulnerability CVE-2025-53770 (Microsoft, 2025.07.19…

Ryukoku.ac.jp 2025-07-21 15:00

Affected Products

Known Exploited Vulnerability

This vulnerability is actively being exploited in the wild

View KEV Details

Remediation Status

Overdue

Due Date

July 23, 2025

Added to KEV

July 22, 2025

Required Action

CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Affected Product

Vendor/Project: Microsoft
Product: SharePoint

Ransomware Risk

Known Ransomware Use
KEV Catalog Version: 2025.07.22 Released: July 22, 2025

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected Products (ENISA)

microsoft
microsoft sharepoint server 2019

ENISA Scoring

CVSS Score (3.1)

8.8
/10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

EPSS Score

0.300
probability

Data provided by ENISA EU Vulnerability Database. Last updated: July 22, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-mh5q-j7vq-g5g7

Advisory Details

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: July 8, 2025, Modified: July 22, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

36 posts
Reddit 4 weeks, 2 days ago
falconupkid

CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities CISA published a Malware Analysis Report (MAR) with analysis and associated detection signatures on files related to Microsoft SharePoint vulnerabilities: CVE-2025-49704 [CWE-94: Code Injection], CVE-2025-49706 [CWE-287: Improper... **CVEs:** CVE-2025-49704,CVE-2025-49706,CVE-2025-53770,CVE-2025-53771 **Source:** https://www.cisa.gov/news-events/alerts/2025/08/06/cisa-releases-malware-analysis-report-associated-microsoft-sharepoint-vulnerabilities

Reddit 4 weeks, 2 days ago
falconupkid

MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any... **CVEs:** CVE-2025-49704,CVE-2025-49706,CVE-2025-53770,CVE-2025-53771 **Source:** https://www.cisa.gov/news-events/analysis-reports/ar25-218a

Reddit 1 month ago
crstux
Exploit

🔥 Top 10 Trending CVEs (04/08/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-54136](https://nvd.nist.gov/vuln/detail/CVE-2025-54136)** - 📝 Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted …

3
3.0
View Original High Risk
Reddit 1 month ago
crstux
Exploit

🔥 Top 10 Trending CVEs (03/08/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2024-38018](https://nvd.nist.gov/vuln/detail/CVE-2024-38018)** - 📝 Microsoft SharePoint Server Remote Code Execution Vulnerability - 📅 **Published:** 10/09/2024 - 📈 **CVSS:** 8.8 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - 📣 **Mentions:** 1 - ⚠️ **Priority:** 2 - …

2
2.0
View Original High Risk
Reddit 1 month, 1 week ago
Helpful_ruben

Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations Key Findings Introduction Check Point Research (CPR) has been closely monitoring the ongoing exploitation of a group of Microsoft SharePoint Server vulnerabilities collectively referred to as “ToolShell.” These active attacks leverage four vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—and are attributed to multiple China affiliated …

Reddit 1 month, 1 week ago
crstux
Exploit

🔥 Top 10 Trending CVEs (30/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2023-2533](https://nvd.nist.gov/vuln/detail/CVE-2023-2533)** - 📝 A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary …

2
2.0
View Original High Risk
Reddit 1 month, 1 week ago
zelda_security
Exploit

Confirmed: SharePoint Server zero-days now being used to drop ransomware in the wild Microsoft confirmed last week that multiple CVEs in on-prem SharePoint Server (2016, 2019, Subscription Edition) are now being exploited to deliver ransomware. Attackers are using the exploit chain to gain access, escalate privileges, and drop payloads. According …

1
1.0
View Original High Risk
Reddit 1 month, 1 week ago
crstux
Exploit

🔥 Top 10 Trending CVEs (29/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-31199](https://nvd.nist.gov/vuln/detail/CVE-2025-31199)** - 📝 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4, macOS Sequoia 15.4. An app may be …

1
1.0
View Original High Risk
Reddit 1 month, 1 week ago
Accurate_String_662
Exploit Payload

ToolShell Malware Family Report # Executive Summary ToolShell is a critical malware family that exploits a chain of vulnerabilities in Microsoft SharePoint Server to achieve unauthenticated remote code execution. First observed in July 2025, this malware has been actively exploited by multiple threat actors, including state-sponsored groups, to compromise on-premises …

2
4.0
View Original High Risk
Reddit 1 month, 1 week ago
No_Click_2097
Exploit PoC

ToolShell Attacks SharePoint security vulnerability: Why Secure Infrastructure Matters More Than Ever **Key Questions This Article Answers:** * **Why do SharePoint security vulnerabilities matter?** * **What is the SharePoint ToolShell attack and how did Chinese hackers exploit it?** * **Which organizations were affected by the SharePoint zero-day vulnerabilities?** * **How …

1
1.0
View Original High Risk

References

Published: 2025-07-08T16:58:05.908Z
Last Modified: 2025-08-18T14:27:09.109Z
Copied to clipboard!