CVE-2025-21400

CVSS 3.1 Score 8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 14, 2025
CWE ID 285

Summary

CVE-2025-21400 is a remote code execution vulnerability affecting Microsoft SharePoint Servers. An attacker can exploit this vulnerability by sending a specially crafted file to a SharePoint site, potentially gaining unauthorized access and executing arbitrary code. This can lead to serious security implications, including data theft, unauthorized system access, and even the installation of malware. Microsoft strongly recommends that affected organizations install the latest security patches to mitigate this risk. Failure to do so may leave systems vulnerable to attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft SharePoint Server

Affected Vendors

  • Microsoft