CVE-2019-0604 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.91% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2019-03-05 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft SharePoint Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Microsoft / SharePoint |
| Ransomware use | known |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | sharepoint enterprise server |
| microsoft | sharepoint foundation |
| microsoft | sharepoint server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft SharePoint - Deserialization Remote Code Execution | 2020-01-21 |
References
- http://www.securityfocus.com/bid/106914
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604
- http://www.securityfocus.com/bid/106914
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0604
→ the Explorer · watch your stack · NVD