CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
— CISA
Microsoft SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5508.1000Patch KB5002744 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20027Patch KB5002741 - Upgrade
Upgrade
Microsoft SharePointto a version that resolves this vulnerability.Fixed in 16.0.10417.20027Patch KB5002741 - Upgrade
Upgrade
Microsoft SharePointto a version that resolves this vulnerability.Fixed in 16.0.5508.1000Patch KB5002744 - Compensating control
Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
- Compensating control
Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS), including SharePoint Server 2013 and earlier versions.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49704?
CVE-2025-49704 is classified as a critical severity vulnerability due to its potential for code injection that could allow unauthorized code execution.
How do I fix CVE-2025-49704?
To fix CVE-2025-49704, apply the recommended patches provided by Microsoft for SharePoint Enterprise Server 2016 and SharePoint Server 2019.
What products are affected by CVE-2025-49704?
CVE-2025-49704 affects Microsoft SharePoint Enterprise Server 2016 and Microsoft SharePoint Server 2019.
What type of attack does CVE-2025-49704 enable?
CVE-2025-49704 enables authorized attackers to perform code injection attacks over a network.
Is CVE-2025-49704 exploitable without authentication?
No, CVE-2025-49704 requires authentication, making it exploitable only by authorized users.