【Vulnerability Alert】Two critical security vulnerabilities have been identified in Microsoft SharePoint Server.
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2025101704101414 | Publication Time | 2025/10/17 16:53 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/10/17 16:53 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Two critical security vulnerabilities have been identified in Microsoft SharePoint Server. |
|||
|
[Content] 【CVE-2025-59228,CVSS:8.8】 This is an improper input validation vulnerability that allows an authenticated attacker to execute code remotely over the network. 【CVE-2025-59237,CVSS:8.8】 This is an untrusted data deserialization vulnerability that allows an authenticated attacker to execute code remotely over the network. |
|||
|
[Affected Platform] ● Microsoft SharePoint Server 2019 ● Microsoft SharePoint Server Subion Edition |
|||
|
[Recommended Actions] 【CVE-2025-59228】https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59228 【CVE-2025-59237】https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59237 |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10446-b41fa-1.html |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





