Important CVSS 6.5 EPSS 0.99911 2025-07 archive

Executive Summary

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Overview

6.5
CVSS MEDIUM
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Spoofing
Released Jul 8 2025
Last Updated Jul 8 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.99911 — 0.99965 percentile
NVD CVSS 6.5 MEDIUM — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
Low
INTEGRITY
Low
AVAILABILITY
None
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 5.9

EPSS Score

0.99911
probability of exploitation in the next 30 days
0.99965 percentile - updated 2026-06-21
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Microsoft SharePoint Enterprise Server 2016 5002760 (Security Update) 5002759 (Security Update) Important Spoofing 5002743 Base: 6.5 Temporal: 5.9 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C 16.0.5513.1001 Maybe None Microsoft SharePoint Server 2019 5002754 (Security Update) 5002753 (Security Update) Important Spoofing 5002739 Base: 6.5 Temporal: 5.9 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C 16.0.10417.20037 Maybe None Microsoft SharePoint Server Subscription Edition 5002768 (Security Update) Important Spoofing Maybe

Patches

1 patch
Article Type Restart
5002768 Security Update Maybe

Known Exploits

Acknowledgments

Anonymous, Viettel Cyber Security with Trend Zero Day Initiative