By zerosday cve bot•July 22, 2025•
cves
CVE-2025-49706: Microsoft SharePoint Improper Authentication Vulnerability (Pentest Lab Guide)

CVE-2025-49706: Technical Deep-Dive (Auto Refreshed)
Generated on 2026-03-24T12:46:55.428Z. This file is automatically regenerated every 30 minutes by the CVE AI enrichment job using web sources (NVD, MITRE, CISA KEV, GitHub).
Executive Technical Summary
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- Context preserved from previous revision: Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Notes: TK-CVE-Repo
Technical Details
- CVE: CVE-2025-49706
- KEV date added: 2025-07-22
- KEV due date: 2025-07-23
- NVD published: 2025-07-08
- NVD modified: 2025-10-27
- MITRE modified: 2026-02-26
- CVSS base score: 6.5
- CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- CVSS exploitability score: 3.9
- CVSS impact score: 2.5
- Attack vector: Network
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Scope: Unchanged
- Confidentiality impact: Low
- Integrity impact: Low
- Availability impact: None
Versions and Products Impacted
- microsoft / sharepoint enterprise server (versions: 2016)
- microsoft / sharepoint server (versions: < 16.0.18526.20424)
- microsoft / sharepoint server (versions: 2019)
- Microsoft / Microsoft SharePoint Enterprise Server 2016 (versions: 16.0.0)
- Microsoft / Microsoft SharePoint Server 2019 (versions: 16.0.0)
- Microsoft / Microsoft SharePoint Server Subscription Edition (versions: 16.0.0)
Weakness Classification
- CWE-287
Repositories for Lab Validation (Public Examples)
- DarkFunct/TK-CVE-Repo | stars: 43 | updated: 2026-03-24 | https://github.com/DarkFunct/TK-CVE-Repo
Notes: TK-CVE-Repo - afine-com/research | stars: 9 | updated: 2026-02-17 | https://github.com/afine-com/research
Notes: CVEs, conference materials, research. - Rabbitbong/OurSharePoint-CVE-2025-53770 | stars: 2 | updated: 2026-02-22 | https://github.com/Rabbitbong/OurSharePoint-CVE-2025-53770
Notes: Do you really think SharePoint is safe? - giterlizzi/secdb-feeds | stars: 0 | updated: 2026-03-19 | https://github.com/giterlizzi/secdb-feeds
Notes: SecDB - Security Feeds - rbctee/CVE-2025-53770 | stars: 0 | updated: 2026-02-11 | https://github.com/rbctee/CVE-2025-53770
Notes: Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability (fork from hazcod/CVE-2025-53770)
People and Organizations Mentioned
- microsoft
- SharePoint
- DarkFunct
- afine-com
- Rabbitbong
- giterlizzi
- rbctee
Practical Defensive Validation (Authorized Only)
- Use only isolated environments and systems you own or are explicitly authorized to test.
- Snapshot infrastructure before validation and preserve baseline logs (EDR, SIEM, OS, app).
- Inventory microsoft / sharepoint enterprise server (versions: 2016) assets and confirm exact vulnerable versions with automated checks.
- Patch in staged environments and validate closure with scanners + service health checks.
- Map detections to MITRE ATT&CK tactics relevant to your environment and tune alert quality.
References
- NVD record: https://nvd.nist.gov/vuln/detail/CVE-2025-49706
- MITRE CVE record: https://www.cve.org/CVERecord?id=CVE-2025-49706
- CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- CISA KEV JSON feed: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- KEV notes: CISA Mitigation Instructions: https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770 ; https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ ; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706 ; https://nvd.nist.gov/vuln/detail/CVE-2025-49706
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49706
- https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/
- Repository example: https://github.com/DarkFunct/TK-CVE-Repo
- Repository example: https://github.com/afine-com/research
- Repository example: https://github.com/Rabbitbong/OurSharePoint-CVE-2025-53770
- Repository example: https://github.com/giterlizzi/secdb-feeds
- Repository example: https://github.com/rbctee/CVE-2025-53770
This content is for defensive security training and authorized validation only.
