PatchSiren cyber security CVE debrief
CVE-2025-49704 Microsoft CVE debrief
CVE-2025-49704 is a Microsoft SharePoint code injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-07-22. CISA marks the issue as known to be used in ransomware campaigns and sets a remediation due date of 2025-07-23. Because it is a KEV-listed issue affecting SharePoint, organizations should treat exposure of public-facing deployments as urgent and follow CISA and Microsoft guidance immediately.
- Vendor
- Microsoft
- Product
- SharePoint
- CVSS
- HIGH 8.8
- CISA KEV
- Listed
- Original CVE published
- 2025-07-22
- Original CVE updated
- 2025-07-22
- Advisory published
- 2025-07-22
- Advisory updated
- 2025-07-22
Who should care
SharePoint administrators, vulnerability management teams, security operations, incident responders, and organizations running public-facing Microsoft SharePoint Server deployments. Priority is especially high for any environment running unsupported SharePoint versions or internet-exposed instances.
Technical summary
The supplied corpus identifies CVE-2025-49704 as a Microsoft SharePoint code injection vulnerability. The CISA KEV entry records the product as Microsoft SharePoint, notes known ransomware campaign use, and points defenders to CISA mitigation guidance, Microsoft’s security blog, and the Microsoft Security Response Center advisory. No CVSS score was provided in the supplied data.
Defensive priority
High. CISA has already listed the vulnerability in KEV with a next-day due date, which is a strong indicator of active exploitation risk and urgent remediation needs.
Recommended defensive actions
- Disconnect public-facing SharePoint Server versions that are end-of-life or end-of-service, including SharePoint Server 2013 and earlier.
- For supported SharePoint versions, follow Microsoft’s mitigation and update instructions immediately.
- Review the CISA alert and Microsoft guidance linked in the KEV entry before making remediation changes.
- Inventory all SharePoint deployments, identify internet-facing instances, and confirm whether they are supported and fully patched.
- Treat the issue as urgent if the environment is exposed to the internet or if compensating controls are not available.
- Use incident-response processes to check for signs of compromise on any potentially affected SharePoint servers.
Evidence notes
All statements are limited to the supplied CVE/KEV metadata and the official links listed in the corpus. The only timing facts used are the CVE/publication date of 2025-07-22, CISA KEV addition on 2025-07-22, and KEV due date of 2025-07-23. No CVSS score was provided in the source data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-49704 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-49704
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-49704 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49704
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.