PT-2019-1447 · Microsoft · Sharepoint Server+1

Publicado

2019-02-12

·

Atualizado

2026-03-13

·

CVE-2019-0604

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint versions prior to the fixed version Microsoft SharePoint Enterprise Server (2016) Microsoft SharePoint Foundation (2013) Microsoft SharePoint Server (2010, 2019)
Description A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. This allows an attacker to run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. The vulnerability can be exploited by uploading a specially crafted SharePoint application package to an affected version of SharePoint. Thousands of servers could be exposed to this vulnerability, which has been used in cyberattacks against Middle East government targets.
Recommendations For Microsoft SharePoint versions prior to the fixed version, update to the latest version to resolve the issue. For Microsoft SharePoint Enterprise Server (2016), apply the available patch to fix the vulnerability. For Microsoft SharePoint Foundation (2013) and Microsoft SharePoint Server (2010, 2019), apply the available patches or updates to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable SharePoint application package upload feature until a patch is available. Avoid using the vulnerable EntityInstanceIdEncoder deserialization of untrusted data until the issue is resolved.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00837
CVE-2019-0604
ZDI-19-181

Produtos afetados

Sharepoint Server
Sharepoint Foundation