CVE-2025-49706 is an improper authentication vulnerability in Microsoft SharePoint Enterprise Server and SharePoint Server, allowing unauthenticated attackers to perform spoofing. With a CVSS score of 6.5 (Medium), it can be exploited over the network with low attack complexity, potentially leading to unauthorized access and data manipulation. This CVE is actively exploited, notably by the Storm-2603 group to deploy Warlock ransomware, and has publicly available exploit modules in Metasploit and Nuclei templates. The high EPSS score, FAUCET Risk Score of 100/100, and extensive community discussion and media coverage underscore its critical nature and widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
< 16.0.18526.20424CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.