CVE-2019-0604: critical vulnerability in Microsoft SharePoint Enterprise Server
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA, has a public proof of concept and 2 threat group(s) use it.
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Apply updates per vendor instructions.
Microsoft SharePoint has a critical flaw that allows attackers to run malicious code remotely by uploading a specially crafted application package. The software doesn't properly verify the contents of the package before executing it.
A remote code execution vulnerability in Microsoft SharePoint stems from insufficient validation of application package source markup (CWE-20). An attacker can craft a malicious package and upload it to a vulnerable SharePoint instance; with appropriate permissions, the package is executed without proper source verification, leading to arbitrary code execution in the SharePoint context.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.