Severity
High
Analysis Summary
CVE-2025-53762 CVSS:8.7
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.
CVE-2025-53771 CVSS:6.5
Microsoft SharePoint Server could allow a remote attacker to conduct spoofing attacks, caused by a path traversal vulnerability. An attacker could exploit this vulnerability to perform spoofing over a network.
Impact
- Privilege Escalation
- Gain Access
Indicators of Compromise
CVE
CVE-2025-53762
CVE-2025-53771
Affected Vendors
- Microsoft
Affected Products
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
- Microsoft Purview
Remediation
Refer to Microsoft Website for patch, upgrade, or suggested workaround information.