Hermes CTI

← Back to all reports

vulnerability new

CVE-2025-49704

● HIGH Confidence: 100% · Version 1

Executive summary

Public evidence documents CVE-2025-49704. This report does not assess any organization.

Technical analysis

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

Evidence and sources

Public evidence for CVE-2025-49704 with preserved provenance.

Authoritative Source Advisories
Verified Evidence Claims

CVE-2025-49704 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

100% Confidence Analysis 🔍

IOCs

No public IOC is available.

CVEs and affected products

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

ATT&CK mapping

No ATT&CK mapping is available.

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Public source record: Public source record for CVE-2025-49704.

Confidence and caveats

1.0

⚠️ Public CTI only; no organizational exposure is asserted.

⚠️ CVSS and EPSS metadata were not present in the retrieved evidence payload.