CVE-2018-8300
published 2018-07-11CVE-2018-8300: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…
PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
12.75%
95.8th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint | — | — |
| microsoft | microsoft_sharepoint | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered by a user uploading a specially crafted SharePoint application package — monitor SharePoint for unusual or unauthorized app package uploads ↗
- →Successful exploitation results in code execution under the SharePoint application pool identity and SharePoint server farm account — monitor these process contexts for anomalous child processes or activity ↗
- →Post-patch, psconfig.exe must be run; unexpected or unauthorized execution of psconfig.exe on SharePoint servers could indicate patch-related activity or attacker post-exploitation masquerading ↗
- ·The vulnerability stems from SharePoint failing to validate the source markup of application packages; no public exploit or active exploitation was confirmed at time of disclosure ↗
- ·Microsoft assessed exploitation likelihood as 'Less Likely' for both latest and older software releases at time of disclosure ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r894-c8ph-2pv7: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-14
CVE-2018-8300 [HIGH] CWE-20 GHSA-r894-c8ph-2pv7: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2018-07-10·CVSS 8.8
CVE-2018-8300 [HIGH] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
FAQ: After installing the updates for Microsoft SharePoint, are there any further steps I need to take?
Yes. After installing the
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - July 2018
blogs_talos·2018-07-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - July 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's release addresses 53 new vulnerabilities, 17 of which are rated critical, 34 are rated important, one is rated moderate, and one is rated as low severity. These vulnerabilities impact Windows Operating System, Edge, Internet Explorer and more.
In addition to the 53 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180017, which addresses the vulnerabilities described in the Adobe security bulletin APSB18-24.
## Critical vulnerabilitiesThis month, Microsoft is addressing 17 vulnerabilities that are rated as critical:
CVE-2018-8242 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-
Talos
Microsoft Patch Tuesday - July 2018
blogs_talos·2018-07-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - July 2018
## Microsoft Patch Tuesday - July 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's release addresses 53 new vulnerabilities, 17 of which are rated critical, 34 are rated important, one is rated moderate, and one is rated as low severity. These vulnerabilities impact Windows Operating System, Edge, Internet Explorer and more.
In addition to the 53 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180017 , which addresses the vulnerabilities described in the Adobe security bulletin APSB18-24 .
## Critical vulnerabilities This month, Microsoft is addressing 17 vulnerabilities that are rated as critical:
CVE-2018-8242 - Scripting Engin
http://www.securityfocus.com/bid/104614http://www.securitytracker.com/id/1041261https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8300http://www.securityfocus.com/bid/104614http://www.securitytracker.com/id/1041261https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8300
2018-07-11
Published