ZeroHour

CVE-2025-21400

mass1

Improper Authorization Leads to Remote Code Execution in Microsoft SharePoint Server

CVSS 3.1
8.0 high
EPSS
34%p98
Published
()
Modified
AI analysis

CVE-2025-21400 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper authorization (CWE-285). According to the CVSS vector, exploitation occurs over the network with low attack complexity, but requires the attacker to hold low-privileged (authenticated) credentials and involves user interaction to trigger. Successful exploitation could allow arbitrary code execution in the context of the SharePoint server, with high impact on confidentiality, integrity, and availability. Organizations running affected on-premises SharePoint Server deployments are affected; the fix shipped in Microsoft's February 2025 Patch Tuesday, which addressed 63 vulnerabilities. There is no public proof-of-concept and no confirmed in-the-wild exploitation yet, but the high EPSS score (34.5%, 98th percentile) suggests a substantial probability of exploitation within 30 days.

What to do: Apply the February 2025 security updates from Microsoft for all affected SharePoint Server versions as soon as possible, prioritizing internet-facing servers. Until patched, restrict network access to SharePoint from untrusted sources and review authentication and application logs for anomalous activity. No public PoC or in-the-wild exploitation is known, but the elevated EPSS probability warrants treating this patch cycle as high priority.

Affected
Microsoft SharePoint Server (on-premises)
Estimated exposure
mass≈100,000+ internet-exposed SharePoint servers, with total on-premises deployments plausibly in the hundreds of thousands (well over 1 million enterprise users) — Estimate based on public internet-exposure scans that have historically shown roughly 100,000+ SharePoint Server hosts reachable online and on SharePoint Server's long-standing, widespread enterprise on-premises install base; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft SharePoint Server Remote Code Execution Vulnerability

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news