CVE-2025-53770

CVE-2025-53770

Information

CVE_ID              : CVE-2025-53770
Severity            : CRITICAL
Published        : 2025-07-20T01:15:30.777
LastModified  : 2025-07-30T01:00:01.490
Updated          : 2025-07-30T01:00:01.490
Status              : Analyzed

Descriptions:

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.


Know Exploitability

Exploitability : False

Vendor Affected

microsoft

CVE-2025-53770

V4.0

V3.1

Score : 9.8
Severity : CRITICAL
Attack Vector : NETWORK
Attack Complexity : LOW
Privileges Required : NONE
User Interaction : NONE
Scope : UNCHANGED
Confidentiality Impact : HIGH
Integrity Impact : HIGH
Availability Impact : HIGH
Exploitability : 3.9
Impact Score : 5.9

V3.0

V2.0

Vendor Product
microsoft
  • sharepoint_server****subscription
  • sharepoint_server2016***enterprise
  • sharepoint_server2019****