CVE-2025-49706: Microsoft SharePoint Improper Authentication Vulnerability
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.
— CISA
Microsoft SharePoint Server Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.18526.20424Patch KB5002751 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20027Patch KB5002741 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5508.1000Patch KB5002744
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49706?
CVE-2025-49706 is considered a high severity vulnerability due to improper authentication in Microsoft Office SharePoint.
How do I fix CVE-2025-49706?
To fix CVE-2025-49706, apply the relevant security patches provided by Microsoft for your version of SharePoint.
Which versions of SharePoint are affected by CVE-2025-49706?
CVE-2025-49706 affects Microsoft SharePoint Server 2019, SharePoint Enterprise Server 2016, and SharePoint Server Subscription Edition.
What type of attack can CVE-2025-49706 facilitate?
CVE-2025-49706 allows an authorized attacker to perform spoofing attacks over a network.
Is there a recommended approach to mitigate CVE-2025-49706?
The recommended approach to mitigate CVE-2025-49706 is to implement the latest updates and security patches from Microsoft.