CVE-2025-54897: Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54897?
CVE-2025-54897 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2025-54897?
To mitigate CVE-2025-54897, apply the security updates provided by Microsoft for affected SharePoint versions.
What products are affected by CVE-2025-54897?
CVE-2025-54897 affects Microsoft SharePoint Server 2019, SharePoint Enterprise Server 2016, and SharePoint Server Subscription Edition.
What type of vulnerability is CVE-2025-54897?
CVE-2025-54897 is a deserialization vulnerability that allows an authorized attacker to execute code remotely.
Who can be impacted by CVE-2025-54897?
Organizations using the affected versions of Microsoft SharePoint may be at risk if they do not patch this vulnerability.