CyberICT

CVE-2025-49704

Microsoft · Published July 8, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected Products

  • Sharepoint Server

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H