CVE-2025-47166
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Affected products
- Sharepoint Server
- Microsoft Sharepoint Enterprise Server
- = 2016
- Microsoft Sharepoint Server
- < 16.0.18526.20396, 2019
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 15.2% (97th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2025-06-10
CVE-2025-47166 at NVD
2 known exploits for CVE-2025-47166
Proof-of-concept code and exploit modules indexed by Sploitus