KB5002805: Removes the denied Write permission for the WSS _WPG and IIS_IURS groups
Description of the security update for SharePoint Server 2016: November 11, 2025 (KB5002805)
This security update resolves Microsoft SharePoint Remote Code Execution Vulnerability. To learn more about the vulnerabilities, see Microsoft Common Vulnerabilities and Exposures CVE-2025-62204.
This public update delivers Feature Pack 2 for SharePoint Server 2016. Feature Pack 2 contains the following feature:
- SharePoint Framework (SPFx)
This public update also delivers all the features that were included in Feature Pack 1 for SharePoint Server 2016, including:
- Administrative Actions Logging
- MinRole enhancements
- SharePoint Custom Tiles
- Hybrid Taxonomy
- OneDrive API for SharePoint on-premises
- OneDrive for Business modern user experience (available to Software Assurance customers)
Improvements and fixes
This security update contains improvements and fixes for the following nonsecurity issue in SharePoint Server 2016.
- Removes the denied Write permission for the WSS _WPG and IIS_IURS groups to resolve failures that occur during newer update installations.

