First published: Tue May 13 2025(Updated: )
<p>Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server | ||
Microsoft SharePoint Server 2019 | ||
Microsoft SharePoint Server Subscription Edition |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30382 is classified as a critical vulnerability due to its potential to allow unauthorized code execution.
To mitigate CVE-2025-30382, update your Microsoft SharePoint software to the latest security patch provided by Microsoft.
CVE-2025-30382 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
CVE-2025-30382 allows unauthorized attackers to execute arbitrary code on the affected SharePoint servers.
Yes, if exploited, CVE-2025-30382 can lead to severe data breaches and compromise sensitive information stored in SharePoint.