LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 22, 2025
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)Ransomware-linked
8.8
CVSS score
High
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 23, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-49704 to its Known Exploited Vulnerabilities catalog on Jul 22, 2025, with a federal patch deadline of Jul 23, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2025-49704 is a code injection vulnerability in Microsoft SharePoint that can allow an authorized attacker to execute code over a network. It matters because SharePoint often sits at the center of document collaboration and internal portals; successful abuse can give attackers a foothold for further movement, data access, or ransomware deployment. Public reporting notes this issue can be chained with CVE-2025-49706, and CVE-2025-53770 is described as a patch bypass for CVE-2025-49704 whose updates provide more robust protection. Confirm all version and fix details against the current Microsoft and CISA advisories.

How it works

The weakness is classified as CWE-94 (code injection). In this class of flaw, an application improperly handles input that is later treated as executable code or script. An authorized attacker who can reach the vulnerable SharePoint surface over the network may inject malicious code that the server then executes in its own context. Exact injection points, request formats, and preconditions are not detailed in the provided facts; treat any public proof-of-concept claims cautiously and verify mechanics only against the vendor advisory. Because the attacker must already be authorized, the risk is highest where authentication is weak, accounts are over-privileged, or SharePoint is exposed more broadly than intended. Chaining with related SharePoint issues can expand impact beyond a single code-execution event.

Am I affected? How to find it in your systems

Microsoft SharePoint is commonly deployed as on-premises SharePoint Server (often behind reverse proxies or load balancers) or as SharePoint Online / Microsoft 365 services. Inventory every instance:

Telemetry to review includes unusual process creation or script execution under SharePoint worker processes, unexpected web requests that result in high-privilege activity, new or modified web parts/pages after authentication, and authentication logs showing lateral use of service accounts. Correlate with ransomware indicators if you already suspect compromise, since this vulnerability has known ransomware use.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2025-49704 and, where available, the more robust updates associated with CVE-2025-53770 (the reported patch bypass). Follow the exact package and installation order published in the vendor advisory; do not assume a single cumulative update covers every related issue. After patching:

If you can't patch immediately

Reduce exposure until the vendor updates can be installed:

If your data may have been exposed

Actively exploited vulnerabilities, especially those with known ransomware use, frequently lead to data theft or encryption. Assume that any SharePoint content reachable by the compromised identity could have been accessed. Rotate credentials for affected accounts and service principals, review audit logs for data exfiltration, and follow your incident-response plan for containment and recovery. You can also run a free exposure scan of your email address against known breach data to check whether related credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-94
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedJul 8, 2025
Added to CISA KEVJul 22, 2025
Federal patch deadlineJul 23, 2025
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities