VDB

CNVD-2025-16687

CNVD-2025-16687 PUBLISHED CVSS 6.5 MEDIUM

SharePoint Server是微软提供的本地部署的企业协作平台,支持内容共享、知识管理和应用整合,可与 Microsoft 365订阅无缝对接以获取最新功能。 Microsoft SharePoint Server存在欺骗漏洞,该漏洞源于Microsoft Office SharePoint不当的身份验证,攻击者可利用漏洞通过网络发起欺骗攻击。

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C

Affected Products

VendorProductVersions
MicrosoftMicrosoft SharePoint Enterprise Server 201616.0.0
microsoftsharepoint_server_201916.0.0
microsoftsharepoint_server_201616.0.0
MicrosoftMicrosoft SharePoint Server Subscription Edition16.0.0
MicrosoftMicrosoft SharePoint Server 201916.0.0
microsoftsharepoint_server16.0.0

Timeline

  • May 1, 2025 CVE Published
  • Jul 8, 2025 PoC Published
  • Jul 8, 2025 PoC Published
  • Jul 14, 2025 PoC Published
  • Jul 19, 2025 PoC Published
  • Jul 19, 2025 PoC Published
  • Jul 19, 2025 PoC Published
  • Jul 19, 2025 PoC Published
  • Jul 20, 2025 PoC Published
  • Jul 20, 2025 PoC Published
  • Jul 20, 2025 PoC Published
  • Jul 20, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›