CVE-2019-0594
published 2019-03-05CVE-2019-0594: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…
PriorityP258high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
12.39%
95.8th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_foundation | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attacker must upload a specially crafted SharePoint application package to trigger the vulnerability; monitor for unusual or unauthorized application package uploads to SharePoint. ↗
- →Successful exploitation results in code execution under the SharePoint application pool identity and the SharePoint server farm account; monitor these process/account contexts for anomalous activity. ↗
- →The root cause is failure to check source markup of an application package; inspect SharePoint app package uploads for malicious markup as a detection/prevention control. ↗
- ·Exploitation requires the attacker to have sufficient SharePoint rights to upload an application package; this is not an unauthenticated attack vector. ↗
- ·At time of advisory publication, exploitation had not been observed in the wild and was rated 'Exploitation Less Likely' for both latest and older software releases. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf89-xg9v-q7v4: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2019-0594 [CRITICAL] CWE-20 GHSA-gf89-xg9v-q7v4: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
GHSA
GHSA-6mr5-xh3f-7vqm: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2019-0604 [HIGH] CWE-20 GHSA-6mr5-xh3f-7vqm: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2019-02-12·CVSS 8.8
CVE-2019-0594 [HIGH] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
Microsoft Office SharePoint: Microsoft Office SharePoint
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Ex
No detection rules found.
No public exploits indexed.
Qualys
February 2019 Patch Tuesday – 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns
blogs_qualys·2019-02-12·CVSS 8.8
[HIGH] February 2019 Patch Tuesday – 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns
This month’s Patch Tuesday is very large, with 74 vulns being addressed of which 20 are labeled as critical. Fifteen of these critical vulns are in the Scripting Engine and browsers, with the remainder being GDI+, SharePoint, and DHCP. Microsoft also issued an Advisory for an Exchange 0-day, along with a patch for one of the two reported vulns. Adobe also released updates for Acrobat/Reader, Flash, Coldfusion, and Creative Cloud.
## Workstation Patches
Browser, Scripting Engine, and GDI+ patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Exchange
In late January, a 0-day exploit was announced for Microsoft Exchange.
Qualys
February 2019 Patch Tuesday - 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns | Qualys
blogs_qualys·2019-02-12·CVSS 8.8
[HIGH] February 2019 Patch Tuesday - 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns | Qualys
This month’s Patch Tuesday is very large, with 74 vulns being addressed of which 20 are labeled as critical. Fifteen of these critical vulns are in the Scripting Engine and browsers, with the remainder being GDI+, SharePoint, and DHCP. Microsoft also issued an Advisory for an Exchange 0-day, along with a patch for one of the two reported vulns. Adobe also released updates for Acrobat/Reader, Flash, Coldfusion, and Creative Cloud.
### Workstation Patches
Browser, Scripting Engine, and GDI+ patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Exchange
In late January, a 0-day exploit was announced for Microsoft Exchange
2019-03-05
Published