CVE-2025-21393: Microsoft SharePoint Server Spoofing Vulnerability
Published Jan 14, 2025
·Updated
Microsoft SharePoint Server Spoofing Vulnerability
Affected Software
6 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Server 2019
Microsoft SharePoint Server<16.0.17928.20356
Microsoft SharePoint Server=2016
Microsoft SharePoint Server=2019
Microsoft SharePoint Enterprise Server 2016
Remediation
Event History
Jan 14, 2025
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverity
Oct 12, 57019
Event
via FIRST·07:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-21393?
CVE-2025-21393 is classified as a moderate severity spoofing vulnerability affecting Microsoft SharePoint Server.
2
How do I fix CVE-2025-21393?
To fix CVE-2025-21393, you need to apply the latest security updates provided by Microsoft for your version of SharePoint.
3
Which versions of SharePoint are affected by CVE-2025-21393?
CVE-2025-21393 affects Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
4
What type of vulnerability is CVE-2025-21393?
CVE-2025-21393 is a spoofing vulnerability that can allow an attacker to impersonate a legitimate user.
5
Can I mitigate CVE-2025-21393 without applying the patch?
Mitigation without applying the patch is not recommended as it may leave your system vulnerable to exploitation.