CVE-2025-29793
largeDeserialization RCE in On-Premises Microsoft SharePoint Server
CVE-2025-29793 is a deserialization flaw (CWE-502) in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network by sending crafted serialized data to the on-premises SharePoint service. Per the CVSS vector (AV:N/AC:L/PR:H/UI:N), the attack is network-based, low in complexity, and requires no user interaction, but the attacker must hold high privileges, such as an admin-level authenticated account, on the SharePoint deployment. Successful exploitation yields code execution in the context of the SharePoint server, enabling full server compromise, access to stored content, and a foothold for lateral movement or ransomware in enterprise networks. Organizations running SharePoint Server or SharePoint Enterprise Server on-premises are affected; SharePoint Online/Microsoft 365 is not in the affected product list, and specific version ranges should be taken from Microsoft's advisory. As of the provided data the flaw is not in CISA KEV and no public PoC is known, but EPSS is elevated at 22.5% (98th percentile), and related coverage of the April 2025 Patch Tuesday notes one of that batch's zero-days was actively exploited in ransomware attacks, making prompt patching advisable.
What to do: Apply the SharePoint security update from Microsoft's April 2025 Patch Tuesday release and verify that supported SharePoint Server builds are current. Audit which accounts hold high privileges (farm/administrative roles) on SharePoint, enforce least privilege, and restrict direct internet exposure of SharePoint servers where it is not required. Review SharePoint and IIS logs for unusual authenticated requests and monitor for exploitation activity given the high EPSS score.
| microsoft SharePoint Enterprise Server | — |
| microsoft SharePoint Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sharepoint enterprise server, sharepoint server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H