CVE-2025-21393

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 79

Summary

CVE-2025-21393 is a new vulnerability affecting Microsoft SharePoint Servers, which allows an unauthenticated attacker to perform spoofing attacks. By manipulating specific SharePoint document URLs, an attacker can trick users into believing that they are opening a legitimate document from a trusted source, when in fact it is a malicious one. This can lead to credential harvesting, data theft, or even further compromise of the affected system. Microsoft recommends applying the latest security updates and implementing additional access control measures to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share