CVE-2025-47166 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published June 10, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published June 10, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published June 10, 2025
Microsoft is announcing the availability of the security updates for Microsoft Office 365. Customers running Office 365 should log in ensure you have the latest update to be protected from this vulnerability. See the [Release Notes](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates) for more information.
Published June 10, 2025
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Published June 10, 2025
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Published June 10, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published June 10, 2025
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
Published June 10, 2025
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Published June 10, 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published June 10, 2025
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
Published June 10, 2025
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.