Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Microsoft SharePoint Path Traversal Vulnerability Allowing Spoofing

Vulnerability

A path traversal vulnerability has been identified in Microsoft Office SharePoint, allowing an authorized attacker to perform spoofing over the network. This issue arises from improper limitations on file paths, enabling exploitation by manipulating directory access.

Impact

Exploitation of this vulnerability could lead to unauthorized spoofing attacks over the network.

Reproduction

The vulnerability can be reproduced by an authorized user who manipulates file paths to traverse directories, potentially leading to spoofing actions on the network.

Remediation

Microsoft has released a security update for SharePoint Subscription Edition. For SharePoint 2019 and 2016, security updates are in progress. In the meantime, users are advised to enable AMSI integration and deploy Defender AV on all SharePoint servers. After applying the update or enabling AMSI, it's recommended to rotate the SharePoint Server ASP.NET machine keys.

Added: Jul 20, 2025, 11:19 PM
Updated: Jul 21, 2025, 12:17 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
6.6
remediation
8.3
relevance
0.3
threat
8.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.