KEV · Activement exploitée
CVE-2025-49706
CVE-2025-49706 est activement exploitée (catalogue CISA KEV) : sévérité medium (CVSS 6.5), 0 apps suivies concernées, aucune encore exposée en version courante.
- Gravité (CVSS)
- 6.5
- Exploitation
- Avérée
- Apps suivies
- 0
- Encore exposées
- 0
Échelle NVD
CISA KEV · EPSS prédit 98.8 %
EN Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Vecteur d'attaque : Réseau
Aucun privilège requis
Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
98.84%
modèle prédictif ; la CISA constate une exploitation avérée
percentile 99.9%
CISA Known Exploited Vulnerability
- Ajouté au KEV
- 2025-07-22
- Deadline remédiation
- 2025-07-23
- Action requise
- Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
- Ransomware
- Oui, campagne ransomware connue