CRITICAL

CVE-2025-53770

Microsoft Sharepoint Server 2025-07-20 CVSS v3.1
CVSS
9.8
KEV

Description

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

Summary dbcve.org

A deserialization vulnerability in on-premises Microsoft SharePoint Server allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted requests. The vulnerability has a CVSS score of 9.8 (Critical) and active exploits are known to exist in the wild.

Mitigation

Implement the mitigation referenced in Microsoft's CVE documentation while awaiting the comprehensive security update; typical mitigations for deserialization vulnerabilities include network segmentation, restricting unnecessary network exposure, and implementing Web Application Firewall rules.

Proof of Concept

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE