CVE-2025-47172: Microsoft SharePoint Server Remote Code Execution Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft SharePoint Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47172?
CVE-2025-47172 is classified as a critical vulnerability due to its potential for SQL injection attacks that can allow unauthorized code execution.
How do I fix CVE-2025-47172?
To fix CVE-2025-47172, apply the latest security patches provided by Microsoft for SharePoint Server products affected by this vulnerability.
What versions of Microsoft SharePoint are affected by CVE-2025-47172?
CVE-2025-47172 affects Microsoft SharePoint Server 2019, SharePoint Server Subscription Edition, and SharePoint Enterprise Server 2016.
What type of attack does CVE-2025-47172 enable?
CVE-2025-47172 enables SQL injection attacks, allowing attackers to execute arbitrary code over a network.
Who is impacted by CVE-2025-47172?
Authorized users of Microsoft SharePoint products who do not have the latest security updates are susceptible to the risks associated with CVE-2025-47172.