CVE-2025-49704
KEV RANSOMWAREHIGH 8.8EPSS 100.0%
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-07-22, used in ransomware campaigns
- Published
- 2025-07-08
- Updated
- 2026-02-13
Proof-of-concept exploits (5)
- https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-o…
- Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell0★ · 2025-09-24
- Salehswt/SharePoint-CVEs-Hunter0★ · 2025-07-22
- khizar-anjum/risky-business-mcp4★ · 2025-08-17
- saladin0x1/CVE-2025-537704★ · 2025-09-04