7

CVE-2025-30378

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Sharepoint Server SwEdition subscription Version < 16.0.18526.20286
Microsoft ≫ Sharepoint Server Version 2016 SwEdition enterprise
Microsoft ≫ Sharepoint Server Version 2019
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.691
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30378
Vendor Advisory