Microsoft Office Sharepoint Server是美国微软(Microsoft)公司的一款为企业客户而设计的、基于web的内容管理和协作工具。该软件初始版本以Office组件形式存在,现在也仍然大大依托于Office,以提供企业门户、文档协同等功能为主,之后版本支持将Office、Exchange、Lync、Project和Visio结合起来。 Microsoft Office Sharepoint Server存在授权问题漏洞。攻击者利用该漏洞执行欺骗攻击。以下产品和版本受到影响:M
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | 16.0.0< 16.0.5508.1000 |
affected |
| Microsoft | Microsoft SharePoint Server 2019 | 16.0.0< 16.0.10417.20027 |
affected |
| Microsoft | Microsoft SharePoint Server Subscription Edition | 16.0.0< 16.0.18526.20424 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | 16.0.0 ~ 16.0.5508.1000 | - |
|
| Microsoft | Microsoft SharePoint Server 2019 | 16.0.0 ~ 16.0.10417.20027 | - |
|
| Microsoft | Microsoft SharePoint Server Subscription Edition | 16.0.0 ~ 16.0.18526.20424 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | A deep dive into CVE-2025-49706 — the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation. | https://github.com/AdityaBhatt3010/CVE-2025-49706-SharePoint-Spoofing-Vulnerability-Under-Active-Exploitation | POC详情 |
| 2 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49706.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2025-47981 | 9.8 CRITICAL | Microsoft SPNEGO Extended Negotiation 安全漏洞 |
| CVE-2025-48817 | 8.8 HIGH | Microsoft Remote Desktop Client 安全漏洞 |
| CVE-2025-49723 | 8.8 HIGH | Microsoft Windows 安全漏洞 |
| CVE-2025-49688 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 资源管理错误漏洞 |
| CVE-2025-49701 | 8.8 HIGH | Microsoft SharePoint 授权问题漏洞 |
| CVE-2025-49687 | 8.8 HIGH | Microsoft Input Method Editor 缓冲区错误漏洞 |
| CVE-2025-49673 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49704 | 8.8 HIGH | Microsoft SharePoint 代码注入漏洞 |
| CVE-2025-49676 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49674 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49672 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49669 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-48824 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49657 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49739 | 8.8 HIGH | Microsoft Visual Studio 后置链接漏洞 |
| CVE-2025-49740 | 8.8 HIGH | Microsoft SmartScreen 安全漏洞 |
| CVE-2025-47998 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-49663 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
| CVE-2025-47986 | 8.8 HIGH | Microsoft Universal Print Management Service 资源管理错误漏洞 |
| CVE-2025-49753 | 8.8 HIGH | Microsoft Windows Routing and Remote Access Service 安全漏洞 |
显示前 20 条,共 129 条。 查看全部 → →
暂无评论