ZeroHour

CVE-2025-29793

large

Deserialization RCE in On-Premises Microsoft SharePoint Server

CVSS 3.1
7.2 high
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2025-29793 is a deserialization flaw (CWE-502) in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network by sending crafted serialized data to the on-premises SharePoint service. Per the CVSS vector (AV:N/AC:L/PR:H/UI:N), the attack is network-based, low in complexity, and requires no user interaction, but the attacker must hold high privileges, such as an admin-level authenticated account, on the SharePoint deployment. Successful exploitation yields code execution in the context of the SharePoint server, enabling full server compromise, access to stored content, and a foothold for lateral movement or ransomware in enterprise networks. Organizations running SharePoint Server or SharePoint Enterprise Server on-premises are affected; SharePoint Online/Microsoft 365 is not in the affected product list, and specific version ranges should be taken from Microsoft's advisory. As of the provided data the flaw is not in CISA KEV and no public PoC is known, but EPSS is elevated at 22.5% (98th percentile), and related coverage of the April 2025 Patch Tuesday notes one of that batch's zero-days was actively exploited in ransomware attacks, making prompt patching advisable.

What to do: Apply the SharePoint security update from Microsoft's April 2025 Patch Tuesday release and verify that supported SharePoint Server builds are current. Audit which accounts hold high privileges (farm/administrative roles) on SharePoint, enforce least privilege, and restrict direct internet exposure of SharePoint servers where it is not required. Review SharePoint and IIS logs for unusual authenticated requests and monitor for exploitation activity given the high EPSS score.

Affected
microsoft SharePoint Enterprise Server
microsoft SharePoint Server
Estimated exposure
largeTens of thousands of internet-exposed on-prem SharePoint servers (hundreds of thousands of deployments overall) — On-premises SharePoint is widely deployed across enterprises and public internet-wide scans have historically surfaced on the order of tens of thousands of SharePoint servers reachable online, though the PR:H requirement limits how many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint enterprise server, sharepoint server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news