CVE-2025-21400HighCVSS 8.0
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.
How could an attacker exploit the vulnerability? In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002685 (Security Update) — fixed build 16.0.5487.1000 KB5002678 (Security Update) — fixed build 16.0.10416.20050 KB5002681 (Security Update) — fixed build 16.0.17928.20396
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21400
- patchhttps://www.microsoft.com/download/details.aspx?familyid=46fe26d2-4dab-4891-97dc-80aa5585c8ee
- referencehttps://support.microsoft.com/help/5002685
- patchhttps://www.microsoft.com/download/details.aspx?familyid=84541f0e-3f75-46d9-a960-91158440a0a9
- referencehttps://support.microsoft.com/help/5002678
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7bfaaf49-deb5-403a-93af-1e00b622ea0e
- referencehttps://support.microsoft.com/help/5002681