VDB

CVE-2025-49706

CVE-2025-49706 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

21. Juli 2025 Microsoft hat außerhalb des regulären Patchzyklus Informationen zu, sowie Sicherheitsaktualisierungen für eine kritische Zero-Day-Schwachstelle in Microsoft SharePoint veröffentlicht. Die Sicherheitslücke CVE-2025-53770 wird seit zumindest 18.07.2025 durch Bedrohungsakteure ausgenutzt. Bei der Lücke handelt es sich um eine Variante eines bereits bekannten und behobenen Problems, CVE-2025-49706. CERT.at steht mit nationalen und internationalen Partner:innen im Austausch und informiert Betroffene in Österreich. CVE-Nummer(n): CVE-2025-53770 CVSS Base Score: 9.8

EPSS 99.88% · 100.0th percentile

Risk Scores

CVSS 3.1
9.800000190734863
EPSS Score
99.88%
100.0th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft SharePoint 2019 (on-Premises)
MicrosoftMicrosoft SharePoint 2016 (on-Premises)
MicrosoftMicrosoft SharePoint Server Subscription Edition
MicrosoftMicrosoft SharePoint Server 2010 & 2013 (für diese Versionen werden keine Updates zur Verfügung gestellt)

Timeline

  • Jan 21, 1970 VulnCheck XDB Entry
  • Mar 4, 2024 CrowdSec Sighting
  • Mar 6, 2024 CrowdSec Sighting
  • Mar 7, 2024 CrowdSec Sighting
  • Mar 7, 2024 CrowdSec Sighting
  • Mar 7, 2024 CrowdSec Sighting
  • Mar 7, 2024 CrowdSec Sighting
  • Mar 8, 2024 CrowdSec Sighting
  • Mar 8, 2024 CrowdSec Sighting
  • Jun 17, 2024 CrowdSec Sighting
  • Jun 29, 2024 CrowdSec Sighting
  • Aug 1, 2024 CrowdSec Sighting
Open in Interactive Console →
$ Console Community · 100/wk Open console ›