← Back to browse · API

CVE-2025-49712

Severity
HIGH
CVSS
8.8
EPSS
0.1831
Risk score
41.61
CISA KEV
No
PoC
No
Published
2025-08-12
Modified
2026-02-13
First seen
2026-08-07
Aliases
EUVD-2025-24275, GHSA-MCWW-299H-4WF7
Products
Microsoft:Microsoft SharePoint Enterprise Server 2016 16.0.0 <16.0.5513.1002, Microsoft:Microsoft SharePoint Server 2019 16.0.0 <16.0.10417.20041
Sources
euvd EUVD-2025-24275

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

References