SharePoint Deserialization of Untrusted Data Vulnerability - CVE-2025-53770 - Vulnerability Database

SharePoint Deserialization of Untrusted Data Vulnerability - CVE-2025-53770

Critical
Reference: CVE-2025-53770
Title: SharePoint Deserialization of Untrusted Data Vulnerability
Overview:

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.