Skip to content
COOEY

EXPOSURES › CVE-2025-49704

CVE-2025-49704

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-07-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-49704 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.

A code injection vulnerability in Microsoft SharePoint enables authorized attackers to execute arbitrary code over a network, which can be chained with CVE-2025-49706 for greater impact. This flaw is actively exploited in the wild and linked to ransomware campaigns, posing severe data breach and operational disruption risks to DIB organizations relying on SharePoint for collaboration and document management. Organizations must immediately patch via the robust updates for CVE-2025-53770 and verify their SharePoint environments against KEV indicators.

Shame score — A critical code injection flaw in a widely deployed enterprise platform is actively exploited by ransomware actors, demonstrating severe negligence in patch management and leaving organizations exposed to mass data breaches and operational destruction.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized