May 2025: Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-30378 Published on May 13, 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2025-30378 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2025-30378
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-30378 are published in these products:
Affected Versions
Microsoft SharePoint Enterprise Server 2016:- Version 16.0.0 and below 16.0.5500.1001 is affected.
- Version 16.0.0 and below 16.0.10417.20010 is affected.
- Version 16.0.0 and below 16.0.18526.20286 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.