{"id":"CVE-2025-49706","title":"Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.","summary":"Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-287"],"vendor":"microsoft","product":"sharepoint_enterprise_server","affected":["sharepoint_enterprise_server = 2016","sharepoint_server < 16.0.18526.20424","sharepoint_server = 2019"],"patched":["sharepoint_server 16.0.18526.20424"],"published":"2025-07-08","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-49706","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706","label":"secure@microsoft.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49706","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99063,"epssPercentile":0.99932,"kev":true,"kevDateAdded":"2025-07-22","kevDueDate":"2025-07-23","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-04T05:36:13.041Z","exploits":{"github":1,"githubRepos":["https://github.com/AdityaBhatt3010/CVE-2025-49706-SharePoint-Spoofing-Vulnerability-Under-Active-Exploitation"],"metasploit":["exploit/windows/http/sharepoint_toolpane_rce"],"nuclei":["CVE-2025-49706"],"checkedAt":"2026-09-21T15:27:26.692Z"},"exploitAvailable":true,"slug":"CVE-2025-49706","body":"## Overview\n\nImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.\n\n## Affected\n\n- `sharepoint_enterprise_server = 2016`\n- `sharepoint_server < 16.0.18526.20424`\n- `sharepoint_server = 2019`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sharepoint_server 16.0.18526.20424`","depth":"midnight","depthScore":86,"depthScoreParts":{"impact":35.8,"likelihood":19.8,"exploitation":25,"ransomware":5},"changes":[{"seq":4826,"id":"CVE-2025-49706","ts":1788887209532,"field":"exploit_available","old":"false","new":"true"},{"seq":3709,"id":"CVE-2025-49706","ts":1788886326574,"field":"exploit_available","old":"true","new":"false"},{"seq":2554,"id":"CVE-2025-49706","ts":1788883008134,"field":"exploit_available","old":"false","new":"true"},{"seq":1583,"id":"CVE-2025-49706","ts":1788882408233,"field":"exploit_available","old":"true","new":"false"},{"seq":697,"id":"CVE-2025-49706","ts":1788881845380,"field":"exploit_available","old":"false","new":"true"}]}