Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2019-0604

Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

cat cve-2019-0604.json
Vendor
Microsoft
Product
SharePoint
CVSS
9.8
EPSS (exploit probability)
99.8%
Status
kevransomware use
CISA patch-by (BOD 22-01)
Published

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-03. Required action per CISA: Apply updates per vendor instructions. Due date: 2022-05-03.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.