Skip to content
COOEY

EXPOSURES › CVE-2019-0604

CVE-2019-0604

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-0604 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 ransomwarerceexploited-in-wild

Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Microsoft faced severe fallout for CVE-2019-0604, a critical remote code execution flaw in SharePoint that allowed attackers to execute arbitrary code with high privileges. The vulnerability was explo
cooey ↗ severe-fallout -0.60
The NVD entry describes the vulnerability's technical severity but does not directly comment on Microsoft's handling. However, the fact that it was exploited in the wild before patching, as noted in b
"Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account."
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized