CVE-2025-59237: Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59237?
CVE-2025-59237 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-59237?
To fix CVE-2025-59237, apply the latest security patches released by Microsoft for the affected SharePoint products.
Which versions of SharePoint are affected by CVE-2025-59237?
CVE-2025-59237 affects Microsoft SharePoint Server 2019, SharePoint Server Subscription Edition, and SharePoint Enterprise Server 2016.
What are the consequences of exploiting CVE-2025-59237?
Exploiting CVE-2025-59237 allows an authorized attacker to execute arbitrary code on the affected system.
Is there a workaround for CVE-2025-59237 before I can apply the patch?
Currently, there are no known workarounds for CVE-2025-59237, so applying the patch is essential for protection.