Improper Authorization in Microsoft products - CVE-2025-29794

 

Improper Authorization in Microsoft products - CVE-2025-29794

Published: April 9, 2025


Vulnerability identifier: #VU107287
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-29794
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to insufficient authorization controls in Microsoft SharePoint. A remote user can bypass authorization and execute arbitrary code on the target system.


Affected software

Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server

How to mitigate CVE-2025-29794

Install updates from vendor's website.


External References

Related Security Bulletins