CVE-2025-49712: Microsoft SharePoint Remote Code Execution Vulnerability
Published Aug 12, 2025
·Updated
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
6 affected componentsFixes available
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server=2016
Microsoft SharePoint Server=2019
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Event History
Aug 14, 2024
News Published
12:45 AM
Aug 12, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via The Register·11:34 PM
News Published
via The Register·11:38 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-49712?
CVE-2025-49712 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2025-49712?
To fix CVE-2025-49712, apply the latest security patches provided by Microsoft for affected SharePoint versions.
3
Which versions of SharePoint are affected by CVE-2025-49712?
CVE-2025-49712 affects Microsoft SharePoint Server 2019 and SharePoint Enterprise Server 2016.
4
What type of vulnerability is CVE-2025-49712?
CVE-2025-49712 is a deserialization vulnerability that allows unauthorized code execution over a network.
5
What can an attacker do with CVE-2025-49712?
An attacker exploiting CVE-2025-49712 can execute arbitrary code, potentially compromising the security of the SharePoint server.