« Volver al listado

Microsoft

Microsoft Sharepoint Enterprise Server: vulnerabilidades y CVE

Microsoft Sharepoint Enterprise Server tiene 256 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 5 figuran en el catálogo de explotación activa de CISA.

CVE256
Últimos 12 meses0
Críticas3
Explotadas activamente5

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-49706Media (6.5)99%⚠ Explotación activa8 jul 2025
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2023-24955Alta (7.2)85%⚠ Explotación activa9 may 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2017-11826Alta (7.8)81%⚠ Explotación activa13 oct 2017
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office…
CVE-2019-0604Crítica (9.8)100%⚠ Explotación activa5 mar 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE…
CVE-2020-1147Alta (7.8)94%⚠ Explotación activa14 jul 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-54905Alta (7.1)0.63%—9 sept 2025
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2025-53736Media (6.2)0.50%—12 ago 2025
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2025-53733Alta (8.4)0.55%—12 ago 2025
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49706Media (6.5)99%⚠ Explotación activa8 jul 2025
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-47994Alta (8.6)3.0%—8 jul 2025
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47172Alta (8.8)1.7%—10 jun 2025
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47169Alta (7.8)0.65%—10 jun 2025
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47168Alta (7.8)0.64%—10 jun 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47166Alta (8.8)21%—10 jun 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47163Alta (8.8)20%—10 jun 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-29820Alta (7.8)0.77%—8 abr 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-29794Alta (8.8)5.1%—8 abr 2025
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-29793Alta (7.2)24%—8 abr 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-27747Alta (7.8)0.82%—8 abr 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2023-38177Media (6.8)3.4%—14 nov 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-24955Alta (7.2)85%⚠ Explotación activa9 may 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-24954Media (6.5)1.8%—9 may 2023
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2023-24950Media (6.5)67%—9 may 2023
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-21717Alta (8.8)1.1%—14 feb 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-21716Crítica (9.8)85%—14 feb 2023
Microsoft Word Remote Code Execution Vulnerability
CVE-2022-44693Alta (8.8)2.0%—13 dic 2022
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-41122Media (6.5)1.6%—9 nov 2022
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2022-41103Media (5.5)0.92%—9 nov 2022
Microsoft Word Information Disclosure Vulnerability
CVE-2022-41062Alta (8.8)1.6%—9 nov 2022
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-41061Alta (7.8)1.2%—9 nov 2022
Microsoft Word Remote Code Execution Vulnerability
CVE-2022-41060Media (5.5)0.79%—9 nov 2022
Microsoft Word Information Disclosure Vulnerability
CVE-2022-38053Alta (8.8)76%—11 oct 2022
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-38009Alta (8.8)2.1%—13 sept 2022
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-38008Alta (8.8)2.0%—13 sept 2022
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-37961Alta (8.8)51%—13 sept 2022
Microsoft SharePoint Server Remote Code Execution Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter4
  2. T1190 Exploit Public-Facing Application4
  3. T1059.001 PowerShell1
  4. T1059.003 Windows Command Shell1
  5. T1068 Exploitation for Privilege Escalation1
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft