Date Posted: 2025/10/20
[Vulnerability Alert] Two Major Security Vulnerabilities Found in Microsoft SharePoint Server
- Subject: [Vulnerability Alert] Two Major Security Vulnerabilities Found in Microsoft SharePoint Server
- Content:
- Forwarded from Taiwan Computer Network Emergency Response Team/Coordination Center TWCERTCC-200-202510-00000008
- Microsoft SharePoint Server is an enterprise-grade collaboration platform that provides functions such as document management and team collaboration, serving as a core platform for enterprise information integration.
- [CVE-2025-59228, CVSS: 8.8] This is an Improper Input Validation vulnerability that allows an authenticated attacker to execute code over the network.
- [CVE-2025-59237, CVSS: 8.8] This is a Deserialization of Untrusted Data vulnerability that allows an authenticated attacker to execute code over the network.
- Affected Platforms:
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
- Recommended Action:
- Please apply the patch according to the solutions released on the official website:
- [CVE-2025-59228]
- [CVE-2025-59237]
- References:
Computer and Communications Center
Network Systems Group