EXPOSURES › CVE-2025-49704
CVE-2025-49704
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.
A code injection vulnerability in Microsoft SharePoint enables authorized attackers to execute arbitrary code over a network, which can be chained with CVE-2025-49706 for greater impact. This flaw is actively exploited in the wild and linked to ransomware campaigns, posing severe data breach and operational disruption risks to DIB organizations relying on SharePoint for collaboration and document management. Organizations must immediately patch via the robust updates for CVE-2025-53770 and verify their SharePoint environments against KEV indicators.
Shame score — A critical code injection flaw in a widely deployed enterprise platform is actively exploited by ransomware actors, demonstrating severe negligence in patch management and leaving organizations exposed to mass data breaches and operational destruction.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |