CVE-2019-0604criticalunder attackransomwareCWE-20

CVE-2019-0604: critical vulnerability in Microsoft SharePoint Enterprise Server

Published · Updated

100Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA, has a public proof of concept and 2 threat group(s) use it.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon17 days
Published on NVDMar 6
1st PoC+17d
CISA KEV+973d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 group(s)10 public exploit(s)
Who exploits it — 2

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Microsoft SharePoint has a critical flaw that allows attackers to run malicious code remotely by uploading a specially crafted application package. The software doesn't properly verify the contents of the package before executing it.

Technical detail

A remote code execution vulnerability in Microsoft SharePoint stems from insufficient validation of application package source markup (CWE-20). An attacker can craft a malicious package and upload it to a vulnerable SharePoint instance; with appropriate permissions, the package is executed without proper source verification, leading to arbitrary code execution in the SharePoint context.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.