CVE-2025-53770 is a critical deserialization of untrusted data vulnerability in on-premises Microsoft SharePoint Server, allowing unauthenticated remote code execution. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector and complete compromise potential. This vulnerability is actively exploited in the wild, including in known ransomware campaigns, with public exploit code readily available in Metasploit and Nuclei templates, and significant community discussion. Microsoft is aware of active exploitation and is preparing a comprehensive update, urging immediate application of provided mitigations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.18526.20508CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.