cbcvebase.
CVE-2018-8300
published 2018-07-11

CVE-2018-8300: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…

PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
12.75%
95.8th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint
microsoftmicrosoft_sharepoint
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by a user uploading a specially crafted SharePoint application package — monitor SharePoint for unusual or unauthorized app package uploads
  • Successful exploitation results in code execution under the SharePoint application pool identity and SharePoint server farm account — monitor these process contexts for anomalous child processes or activity
  • Post-patch, psconfig.exe must be run; unexpected or unauthorized execution of psconfig.exe on SharePoint servers could indicate patch-related activity or attacker post-exploitation masquerading
  • ·The vulnerability stems from SharePoint failing to validate the source markup of application packages; no public exploit or active exploitation was confirmed at time of disclosure
  • ·Microsoft assessed exploitation likelihood as 'Less Likely' for both latest and older software releases at time of disclosure

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.