CVE-2025-53771

Media6.5Pubblicata il 20 luglio 2025

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Preallarme: sfruttamento osservato

  • Sfruttamento osservato dal 18 lug 2025
  • Non ancora nel catalogo ufficiale CISA
  • Attaccata 3 giorni prima che la vulnerabilità fosse resa pubblica
  • Usata in campagne ransomware

Fonte: VulnCheck KEV · 1 ott 2026 16 set 2026 1 lug 2026 3 giu 2026 24 mag 2026 18 apr 2026

Punteggio CVSS6.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Tipo di debolezza (CWE)CWE-287
Vendormicrosoft

Prodotti coinvolti

VendorProdottoVersioni
microsoftsharepoint server< 16.0.18526.20508

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE