CVE-2019-0604
published 2019-03-05CVE-2019-0604: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.91%
100.0th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_foundation | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2019-0604 exploitation targets the DecodeEntityInstanceId method within Microsoft.SharePoint.dll via a specially crafted web request to picker.aspx; monitor for anomalous POST requests to this endpoint on SharePoint servers. ↗
- →Post-exploitation activity following CVE-2019-0604 exploitation includes webshell (primarily China Chopper) installation on SharePoint servers; hunt for China Chopper webshell artifacts on SharePoint hosts. ↗
- →Post-exploitation credential dumping via Mimikatz follows CVE-2019-0604 webshell deployment; monitor for Mimikatz execution on SharePoint servers and lateral movement activity. ↗
- →VOID MANTICORE (Iranian MOIS-linked threat actor) has exploited CVE-2019-0604 for initial access to SharePoint servers; correlate SharePoint exploitation with subsequent wiper/destructive payload deployment.
- →Apply Qualys QID 110330 to scan for CVE-2019-0604 exposure; patch with KB4462199, KB4462202, KB4462143, KB4462184, KB4461630, KB4462211 for applicable SharePoint versions. ↗
- ·CVE-2019-0604 exploitation requires the attacker to have special/authenticated rights on the SharePoint server to execute code in the context of the SharePoint application pool and farm account. ↗
- ·Successful exploitation allows arbitrary code execution in the context of the SharePoint application pool and the SharePoint server farm account, not SYSTEM-level by default. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf89-xg9v-q7v4: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2019-0594 [CRITICAL] CWE-20 GHSA-gf89-xg9v-q7v4: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
GHSA
GHSA-6mr5-xh3f-7vqm: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2019-0604 [HIGH] CWE-20 GHSA-6mr5-xh3f-7vqm: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
VulnCheck
Microsoft SharePoint Remote Code Execution Vulnerability
vulncheck·2019·CVSS 9.8
CVE-2019-0604 [CRITICAL] CWE-20 Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
Affected: Microsoft SharePoint
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://threatpost.com/fin7-active-exploits-sharepoint/144628/; https://www.ict-nn.com/fin7-linked-to-escalating-active-exploits-for-microsoft-sharepoint-bug/; https://unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-government-sharepoint-servers/; https://securelist.com/apt-trends-report-q2-2019/91897/; https://blog.sonicwa
CISA
Microsoft SharePoint Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2019-0604 [CRITICAL] CWE-20 Microsoft SharePoint Remote Code Execution Vulnerability
Vulnerability: Microsoft SharePoint Remote Code Execution Vulnerability
Affected: Microsoft SharePoint
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0604
Remediation Due Date: 2022-05-03
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2019-02-12·CVSS 9.8
CVE-2019-0604 [CRITICAL] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
Microsoft Office SharePoint: Microsoft Office SharePoint
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Ex
Suricata
ET WEB_SPECIFIC_APPS Possible SharePoint RCE Attempt (CVE-2019-0604)
suricata·2019-05-10·CVSS 9.8
CVE-2019-0604 [CRITICAL] ET WEB_SPECIFIC_APPS Possible SharePoint RCE Attempt (CVE-2019-0604)
ET WEB_SPECIFIC_APPS Possible SharePoint RCE Attempt (CVE-2019-0604)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible SharePoint RCE Attempt (CVE-2019-0604)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"Picker.aspx?PickerDialogType=Microsoft.SharePoint"; nocase; http.request_body; content:"ctl00|25|24PlaceHolderDialogBodySection|25|24ctl05|25|24hiddenSpanData|3d5f5f|"; nocase; fast_pattern; reference:url,www.zerodayinitiative.com/blog/2019/3/13/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability; classtype:attempted-admin; sid:2027345; rev:4; metadata:attack_target Web_Server, created_at 2019_05_10, cve CVE_2019_0604, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity
Exploit-DB
Microsoft SharePoint - Deserialization Remote Code Execution
exploitdb·2020-01-21
CVE-2019-0604 Microsoft SharePoint - Deserialization Remote Code Execution
Microsoft SharePoint - Deserialization Remote Code Execution
---
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
import requests
import sys
from xml.sax.saxutils import escape
from lxml import html
import codecs
import readline
from clint.arguments import Args
import signal
def serialize_command(cmd):
total = ""
for x in cmd:
a = codecs.encode(x,"utf-16be")
b = codecs.encode(a,"hex").decode('ascii')
total += b[::-1]
return total
def deserialize_command(cmd):
length = len(cmd)
s = ""
for i in range(0,length,4):
character = cmd[i]+cmd[i+1]+cmd[i+2]+cmd[i+3]
character = character[::-1]
c_hex = codecs.decode(character,"hex")
a = codecs.decode(c_hex,"utf-16be")
s += a
return s
#######################################
signal.signal(signal.SIGINT, signal.default_int_handler)
args = Args()
m
Nuclei
Microsoft SharePoint - Remote Code Execution
nuclei·CVSS 9.8
CVE-2019-0604 [CRITICAL] Microsoft SharePoint - Remote Code Execution
Microsoft SharePoint - Remote Code Execution
Microsoft SharePoint contains a remote code execution caused by failure to check the source markup of an application package, letting remote attackers execute arbitrary code, exploit requires sending malicious application package.
Template:
id: CVE-2019-0604
info:
name: Microsoft SharePoint - Remote Code Execution
author: tree-chtsec,pszyszkowski
severity: critical
description: |
Microsoft SharePoint contains a remote code execution caused by failure to check the source markup of an application package, letting remote attackers execute arbitrary code, exploit requires sending malicious application package.
impact: |
Remote attackers can execute arbitrary code on the server, potentially leading to full system compromise.
remediation: |
Fixed
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cybersecurity Snapshot: Ghost Ransomware Group Targets Known Vulns, CISA Warns, While Report Finds Many Cyber Pros Want To Switch Jobs
blogs_tenable·2025-02-21
Cybersecurity Snapshot: Ghost Ransomware Group Targets Known Vulns, CISA Warns, While Report Finds Many Cyber Pros Want To Switch Jobs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
blogs_checkpoint·2024-05-20
CVE-2019-0604 Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
Void Manticore is an Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS). They carr
Bleepingcomputer
New BiBi Wiper version also destroys the disk partition table
blogs_bleepingcomputer·2024-05-20
New BiBi Wiper version also destroys the disk partition table
## New BiBi Wiper version also destroys the disk partition table
## Bill Toulas
A new version of the BiBi Wiper malware is now deleting the disk partition table to make data restoration harder, extending the downtime for targeted victims.
BiBi Wiper attacks on Israel and Albania are linked to a suspected Iranian hacking group named 'Void Manticore' (Storm-842), which is believed to be affiliated with Iran's Ministry of Intelligence and Security (MOIS).
BiBi Wiper was first spotted by Security Joes in October 2023, with its activities prompting an alert from Israel's CERT in November 2023 about large-scale offensive cyber operations using it against critical organizations in the country.
A new report from Check Point Research uncovers newer variants of the BiBi wiper and two other cust
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Trendmicro
CISA Reports Top Vulnerabilities From Remote Work
blogs_trendmicro·2021-09-21·CVSS 9.1
[CRITICAL] CISA Reports Top Vulnerabilities From Remote Work
Exploits & Vulnerabilities
# CISA Reports Top Vulnerabilities From Remote Work
Trend Micro’s Next-Generation IPS protects organizations from threats as attackers now target remote work-related vulnerabilities.
By: Jon Clay
2021/09/21
Read time: ( words)
Save to Folio
As COVID-19 moves people to the cloud, cyber actors now aim at shooting the sky.
On July 28, 2021, the US Cybersecurity and Infrastructure Security Agency (CISA) released a report detailing the top exploited vulnerabilities in 2020 and 2021. The report shows that the attackers’ favorite new targets are vulnerabilities published after 2019 and relevant to remote work, VPN (Virtual Private Network), and cloud-based technologies.
As remote work became widespread, cyber actors have been taking advantage of the young, unpat
Qualys
CISA Alert: Top Routinely Exploited Vulnerabilities | Qualys
blogs_qualys·2021-07-29·CVSS 10.0
[CRITICAL] CISA Alert: Top Routinely Exploited Vulnerabilities | Qualys
#### Table of Contents
- Top Routinely Exploited Vulnerabilities
- Detect CISAs Top Routinely Exploited Vulnerabilities using Qualys VMDR
- Recommendations
- Remediation and Mitigation
- Get Started Now
On July 28, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a cybersecurity advisory detailing the top 30 publicly known vulnerabilities that have been routinely exploited by cyber threat actors in 2020 and 2021. Organizations are advised to prioritize and apply patches or workarounds for these vulnerabilities as soon as possible.
The advisory states, “If an organization is unable to update all software shortly after a patch is released, prioritize implementing patches for CVEs that are already known to be exploited or that would be accessible to the large
Qualys
CISA Alert: Top Routinely Exploited Vulnerabilities
blogs_qualys·2021-07-29·CVSS 9.1
[CRITICAL] CISA Alert: Top Routinely Exploited Vulnerabilities
## Table of Contents
Top Routinely Exploited Vulnerabilities
Detect CISAs Top Routinely Exploited Vulnerabilities using Qualys VMDR
Recommendations
Remediation and Mitigation
Get Started Now
On July 28, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a cybersecurity advisory detailing the top 30 publicly known vulnerabilities that have been routinely exploited by cyber threat actors in 2020 and 2021. Organizations are advised to prioritize and apply patches or workarounds for these vulnerabilities as soon as possible.
The advisory states, “If an organization is unable to update all software shortly after a patch is released, prioritize implementing patches for CVEs that are already known to be exploited or that would be accessible to the largest numbe
Trendmicro
This Week in Security News - April 30, 2021
blogs_trendmicro·2021-04-30·CVSS 9.8
[CRITICAL] This Week in Security News - April 30, 2021
Endpoints
# This Week in Security News - April 30, 2021
Hacktivism’s reemergence explained and Hello ransomware uses updated China Chopper web shell
By: Jon Clay
2021/04/30
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read about the reemergence of hacktivism. Also, learn about the technical features of a new Hello Ransomware attack.
Read on:
Hacktivism’s Reemergence Explained: Data Drops and Defacements for Social Justice
In the past few months, the volume of data made public by hacktivists skyrocketed. Many tend to be politically motivated, but a few also expose ways in which technology can be used against people. In this article, I explain
Trendmicro
Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
blogs_trendmicro·2021-04-27·CVSS 9.8
CVE-2019-0604 [CRITICAL] Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
## Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
We discuss the technical features of a Hello ransomware attack, including its exploitation of CVE-2019-0604 and the use of a modified version of the China Chopper web shell.
By: Janus Agcaoili Apr 27, 2021 Read time: ( words)
Save to Folio
In January, we encountered a new ransomware using .hello as its extension in one of our cases that possibly arrived via a SharePoint server vulnerability. This appeared to be a new ransomware family dubbed as the Hello ransomware (aka WickrMe), named after the chat application that was used to contact the cybercriminals responsible. Previous variants were observed using .hemming and .strike extensions and did not include the cybercriminals’ WickrMe user handles. In con
Trendmicro
Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
blogs_trendmicro·2021-04-27·CVSS 9.8
CVE-2019-0604 [CRITICAL] Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
## Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
We discuss the technical features of a Hello ransomware attack, including its exploitation of CVE-2019-0604 and the use of a modified version of the China Chopper web shell.
By: Janus Agcaoili 2021/04/27 Read time: ( words)
Save to Folio
In January, we encountered a new ransomware using .hello as its extension in one of our cases that possibly arrived via a SharePoint server vulnerability. This appeared to be a new ransomware family dubbed as the Hello ransomware (aka WickrMe), named after the chat application that was used to contact the cybercriminals responsible. Previous variants were observed using .hemming and .strike extensions and did not include the cybercriminals’ WickrMe user handles. In contr
Trendmicro
Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
blogs_trendmicro·2021-04-27·CVSS 9.8
CVE-2019-0604 [CRITICAL] Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
# Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
We discuss the technical features of a Hello ransomware attack, including its exploitation of CVE-2019-0604 and the use of a modified version of the China Chopper web shell.
By: Janus Agcaoili
2021/04/27
Read time: ( words)
Save to Folio
In January, we encountered a new ransomware using .hello as its extension in one of our cases that possibly arrived via a SharePoint server vulnerability. This appeared to be a new ransomware family dubbed as the Hello ransomware (aka WickrMe), named after the chat application that was used to contact the cybercriminals responsible. Previous variants were observed using .hemming and .strike extensions and did not include the cybercriminals’ WickrMe user handles. In contr
Trendmicro
Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
blogs_trendmicro·2021-04-27·CVSS 9.8
CVE-2019-0604 [CRITICAL] Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
## Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability
We discuss the technical features of a Hello ransomware attack, including its exploitation of CVE-2019-0604 and the use of a modified version of the China Chopper web shell.
By: Janus Agcaoili Apr 27, 2021 Read time: ( words)
Save to Folio
In January, we encountered a new ransomware using .hello as its extension in one of our cases that possibly arrived via a SharePoint server vulnerability. This appeared to be a new ransomware family dubbed as the Hello ransomware (aka WickrMe), named after the chat application that was used to contact the cybercriminals responsible. Previous variants were observed using .hemming and .strike extensions and did not include the cybercriminals’ WickrMe user handles. In con
Trendmicro
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
blogs_trendmicro·2021-04-09
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
APT & Targeted Attacks
# Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
This blog details how Iron Tiger threat actors have updated their toolkit with an updated SysUpdate malware variant that now uses five files in its infection routine instead of the usual three.
By: Daniel Lunghi, Kenney Lu
2021/04/09
Read time: ( words)
Save to Folio
Update as of April 27, 2021, 7 A.M. E.T.: We've updated the "Rootkits From a Public Repository" section and the appendix to include a second sample.
More than a year after Operation DRBControl, a campaign by a cyberespionage group that targets gambling and betting companies in Southeast Asia, we found evidence that the Iron Tiger threat actor is still interested in the gambling industry.
This blog details how Iron Tiger threat actors
Qualys
Unpacking the CVEs in the FireEye Breach – Start Here First
blogs_qualys·2021-02-01·CVSS 7.8
CVE-2020-1472 [HIGH] Unpacking the CVEs in the FireEye Breach – Start Here First
In a blog post on Dec. 22, 2020, Qualys revealed it has identified 7.5 million instances of vulnerability to the stolen FireEye Red Team assessment tools across an anonymized set of its 15,700-member customer base.
Of the 7.5 million instances of vulnerability, 99.84% were caused by only 8 CVEs, and over 99% were caused by these five CVEs: CVE-2020-1472, CVE-2019-0604, CVE-2017-11774, CVE-2016-0167 and CVE-2019-0708.
In this article, we examine the five CVEs in detail to:
Help SOC and operational security teams understand the behavioral aspects of these CVEs and plan defensive strategies;
Help threat hunting teams understand their threat attributes and associated attack vectors and take defensive actions against adversaries actively exploiting these CVEs.
From a threat perspective, we
Qualys
Unpacking the CVEs in the FireEye Breach - Start Here First | Qualys
blogs_qualys·2021-02-01·CVSS 7.8
CVE-2020-1472 [HIGH] Unpacking the CVEs in the FireEye Breach - Start Here First | Qualys
In a blog post on Dec. 22, 2020, Qualys revealed it has identified 7.5 million instances of vulnerability to the stolen FireEye Red Team assessment tools across an anonymized set of its 15,700-member customer base.
Of the 7.5 million instances of vulnerability, 99.84% were caused by only 8 CVEs, and over 99% were caused by these five CVEs: CVE-2020-1472, CVE-2019-0604, CVE-2017-11774, CVE-2016-0167 and CVE-2019-0708.
In this article, we examine the five CVEs in detail to:
1. Help SOC and operational security teams understand the behavioral aspects of these CVEs and plan defensive strategies;
2. Help threat hunting teams understand their threat attributes and associated attack vectors and take defensive actions against adversaries actively exploiting these CVEs.
From a threat perspectiv
Qualys
Qualys Security Advisory: SolarWinds / FireEye | Qualys
blogs_qualys·2020-12-22
Qualys Security Advisory: SolarWinds / FireEye | Qualys
#### Qualys Researchers found Millions of devices exposed to vulnerabilities used in the stolen FireEye Red Team tools and SolarWinds Orion by analyzing the anonymized set of vulnerabilities across Qualys’ worldwide customer base
##### Qualys to offer a free 60-day integrated Vulnerability Management, Detection and Response service to help organizations quickly assess the devices impacted by SolarWinds Orion vulnerabilities, SUNBURST Trojan detections, or FireEye Red Team tools, and to remediate them and track their remediation via dynamic dashboards. Register athttps://www.qualys.com/solarhack/
On Dec 8, FireEye disclosed the theft of its Red Team assessment tools which leverage over 16 known CVE’s to exploit client environments to test and validate their security posture. FireEye also
Qualys
Qualys Security Advisory: SolarWinds / FireEye
blogs_qualys·2020-12-22
Qualys Security Advisory: SolarWinds / FireEye
## Qualys Researchers found Millions of devices exposed to vulnerabilities used in the stolen FireEye Red Team tools and SolarWinds Orion by analyzing the anonymized set of vulnerabilities across Qualys’ worldwide customer base
## Qualys to offer a free 60-day integrated Vulnerability Management, Detection and Response service to help organizations quickly assess the devices impacted by SolarWinds Orion vulnerabilities, SUNBURST Trojan detections, or FireEye Red Team tools, and to remediate them and track their remediation via dynamic dashboards. Register at https://www.qualys.com/solarhack/
On Dec 8, FireEye disclosed the theft of its Red Team assessment tools which leverage over 16 known CVE’s to exploit client environments to test and validate their security posture. FireEye also conf
Unit42
Threat Brief: FireEye Red Team Tool Breach
blogs_unit42·2020-12-11
Threat Brief: FireEye Red Team Tool Breach
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: FireEye Red Team Tool Breach
Unit 42
Published: December 10, 2020
High Profile Threats
Malware
Vulnerabilities
FireEye breach
## Executive Summary
On Dec. 8, 2020, one of the leading cybersecurity companies in the industry, FireEye, reported a breach and data exfiltration unlike any that we have seen previously. What makes this attack unique is not only the target, FireEye being a well-known cybersecurity company, but that the stolen data contains the internal, custom-crafted red-team and penetration testing tools used by the company to imitate different threat actors during customer security consultations. FireEye’s blog provided a wealth of information for defenders to implement security controls
Unit42
Threat Brief: FireEye Red Team Tool Breach
blogs_unit42·2020-12-11
Threat Brief: FireEye Red Team Tool Breach
## Executive Summary
On Dec. 8, 2020, one of the leading cybersecurity companies in the industry, FireEye, reported a breach and data exfiltration unlike any that we have seen previously. What makes this attack unique is not only the target, FireEye being a well-known cybersecurity company, but that the stolen data contains the internal, custom-crafted red-team and penetration testing tools used by the company to imitate different threat actors during customer security consultations. FireEye’s blog provided a wealth of information for defenders to implement security controls and mitigations for defense against the stolen tools. This data is being used by Palo Alto Networks to help ensure our customers are protected if the attackers choose to utilize the tools for malicious purposes.
It i
Fortinet
FireEye Red Team Tool Breach | Fortinet
blogs_fortinet·2020-12-11·CVSS 8.8
[HIGH] FireEye Red Team Tool Breach | Fortinet
PSIRT BLOGS
FireEye Red Team Tool Breach
By Carl Windsor | December 11, 2020
Executive Summary
On December 8th cyber security vendor FireEye reported a breach of their network and data exfiltration which included their internally developed Red Team tools. FireEye took the step of publishing details of these tools in a GitHub repository to allow other vendors to protect against their use by potential adversaries.
This breach has been attributed to a nation state threat actor so we do not expect to see these tools be widely abused in the wild, however with the additional information provided by FireEye, Fortinet have been able to ensure that these tools cannot be abused.
Threat Mitigation
None of the vulnerabilities disclosed as targeted in the tools were zero days, therefore FortiGuard
Qualys
Solorigate/Sunburst : Theft of Cybersecurity Tools | FireEye Breach
blogs_qualys·2020-12-10
Solorigate/Sunburst : Theft of Cybersecurity Tools | FireEye Breach
Update Jan 5, 2021 : New patching section with two new dashboard widgets showing the number of missing FireEye-related patches in your environment and the number of assets in your environment missing one of those patches.
Update Dec 23, 2020 : Added a new section on compensating controls.
Update Dec 22, 2020: FireEye disclosed the theft of their Red Team assessment tools. Hackers now have an influential collection of new techniques to draw upon.
Using Qualys VMDR, the vulnerabilities for Solorigate/SUNBURST can be prioritized for the following Real-Time Threat Indicators (RTIs):
Active Attacks
Solorigate Sunburst ( New RTI )
Original post : On December 8, 2020, FireEye disclosed theft of their Red Team assessment tools. These tools are used by FireEye to test and validate the securit
Qualys
Solorigate/Sunburst : Theft of Cybersecurity Tools | FireEye Breach | Qualys
blogs_qualys·2020-12-10
Solorigate/Sunburst : Theft of Cybersecurity Tools | FireEye Breach | Qualys
Update Jan 5, 2021: New patching section with two new dashboard widgets showing the number of missing FireEye-related patches in your environment and the number of assets in your environment missing one of those patches.
Update Dec 23, 2020: Added a new section on compensating controls.
Update Dec 22, 2020: FireEye disclosed the theft of their Red Team assessment tools. Hackers now have an influential collection of new techniques to draw upon.
Using Qualys VMDR, the vulnerabilities for Solorigate/SUNBURST can be prioritized for the following Real-Time Threat Indicators (RTIs):
- Active Attacks
- Solorigate Sunburst (New RTI)
Original post: On December 8, 2020, FireEye disclosed theft of their Red Team assessment tools. These tools are used by FireEye to test and validate the security
Zscaler
SolarWinds CyberAttack and FireEye Red Team Tools Coverage
blogs_zscaler·2020-12-09
SolarWinds CyberAttack and FireEye Red Team Tools Coverage
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Microsoft’s December 2020 Patch Tuesday Addresses 58 CVEs including CVE-2020-25705 (SAD DNS)
blogs_tenable·2020-12-08·CVSS 7.4
[HIGH] Microsoft’s December 2020 Patch Tuesday Addresses 58 CVEs including CVE-2020-25705 (SAD DNS)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s November 2020 Patch Tuesday Addresses 112 CVEs including CVE-2020-17087
blogs_tenable·2020-11-10·CVSS 7.8
[HIGH] Microsoft’s November 2020 Patch Tuesday Addresses 112 CVEs including CVE-2020-17087
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, Sept. 2020 Edition
blogs_krebs·2020-09-23·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday, Sept. 2020 Edition
Microsoft today released updates to remedy nearly 130 security vulnerabilities in its Windows operating system and supported software. None of the flaws are known to be currently under active exploitation, but 23 of them could be exploited by malware or malcontents to seize complete control of Windows computers with little or no help from users.
The majority of the most dangerous or “critical” bugs deal with issues in Microsoft’s various Windows operating systems and its web browsers, Internet Explorer and Edge. September marks the seventh month in a row Microsoft has shipped fixes for more than 100 flaws in its products, and the fourth month in a row that it fixed more than 120.
Among the chief concerns for enterprises this month is CVE-2020-16875, which involves a critical flaw in the
Krebs
Microsoft Patch Tuesday, Sept. 2020 Edition
blogs_krebs·2020-09-08·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday, Sept. 2020 Edition
Microsoft today released updates to remedy nearly 130 security vulnerabilities in its Windows operating system and supported software. None of the flaws are known to be currently under active exploitation, but 23 of them could be exploited by malware or malcontents to seize complete control of Windows computers with little or no help from users.
The majority of the most dangerous or “critical” bugs deal with issues in Microsoft’s various Windows operating systems and its web browsers, Internet Explorer and Edge . September marks the seventh month in a row Microsoft has shipped fixes for more than 100 flaws in its products, and the fourth month in a row that it fixed more than 120.
Among the chief concerns for enterprises this month is CVE-2020-16875 , which involves a critical flaw in th
Tenable
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
blogs_tenable·2020-09-08
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Incident Response Analyst Report of 2019
blogs_securelist·2020-08-06
Incident Response Analyst Report of 2019
Table of Contents
- Executive summary
- Recommendations
- Reasons for incident response
- Distribution of reasons for top regions
- Distribution of reasons for industries
- Initial vectors or how adversaries get in
- Tools and exploits
- Attack duration
- Operational metrics
- How fast we responded
- How long response took
- MITRE ATT&CK tactics and techniques
- Conclusion
Authors
- Ayman Shaaban
- Grigory Sablin
- Kaspersky GERT
Download full report (PDF)
As an incident response service provider, Kaspersky delivers a global service that results in global visibility of adversaries’ cyber-incident tactics and techniques used in the wild. In this report, we share our teams’ conclusions and analysis based on incident responses and statistics from 2019. As well as a range of highlights,
Securelist
Incident Response Analyst Report 2019
blogs_securelist·2020-08-06
Incident Response Analyst Report 2019
Table of Contents
Executive summary
Verticals and industries
Recommendations
Reasons for incident response
Distribution of reasons for top regions
Distribution of reasons for industries
Initial vectors or how adversaries get in
Tools and exploits
30% of all incidents were tied to legitimate tools
Exploits
Attack duration
Operational metrics
False positives rate
Age of attack
How fast we responded
How long response took
MITRE ATT&CK tactics and techniques
Conclusion
Authors
Ayman Shaaban
Grigory Sablin
Kaspersky GERT
Download full report (PDF)
As an incident response service provider, Kaspersky delivers a global service that results in global visibility of adversaries’ cyber-incident tactics and techniques used in the wild. In this report, we share our teams’ conclus
Tenable
Copy-Paste Compromises: Threat Actors Target Telerik UI, Citrix, and SharePoint Vulnerabilities (CVE-2019-18935)
blogs_tenable·2020-07-22·CVSS 9.8
[CRITICAL] Copy-Paste Compromises: Threat Actors Target Telerik UI, Citrix, and SharePoint Vulnerabilities (CVE-2019-18935)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Targeted attacks on Australian Networks | Zscaler Blog
blogs_zscaler·2020-06-18·CVSS 9.8
[CRITICAL] Targeted attacks on Australian Networks | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
blogs_tenable·2020-04-30
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
blogs_tenable·2020-04-13
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Unit42
Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
blogs_unit42·2020-02-03·CVSS 9.8
CVE-2019-0604 [CRITICAL] Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
Threat Research Center
Threat Research
Vulnerabilities
## Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
Robert Falcone
Published: February 3, 2020
Threat Research
Vulnerabilities
China Chopper
CVE-2019-0604
Emissary Panda
Middle East
SharePoint
## Executive Summary
On September 10, 2019, we observed unknown threat actors exploiting a vulnerability in SharePoint described in CVE-2019-0604 to install several webshells on the website of a Middle East government organization. One of these webshells is the open source AntSword webshell freely available on Github , which is remarkably similar to the infamous China Chopper webshell.
On January 10, 2020, we used Shodan to search for Internet accessible servers running versions of
Unit42
Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
blogs_unit42·2020-02-03·CVSS 9.8
CVE-2019-0604 [CRITICAL] Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
## Executive Summary
On September 10, 2019, we observed unknown threat actors exploiting a vulnerability in SharePoint described in CVE-2019-0604 to install several webshells on the website of a Middle East government organization. One of these webshells is the open source AntSword webshell freely available on Github, which is remarkably similar to the infamous China Chopper webshell.
On January 10, 2020, we used Shodan to search for Internet accessible servers running versions of SharePoint vulnerable to CVE-2019-0604. While admittedly the version numbers provided by SharePoint within HTTP responses do not always provide the precise SharePoint version number, we decided to use it to check if it was less than the version numbers of the patched SharePoint versions from the Microsoft advis
Tenable
CVE-2019-0604: Critical Microsoft SharePoint Remote Code Execution Flaw Actively Exploited
blogs_tenable·2019-12-12·CVSS 9.8
[CRITICAL] CVE-2019-0604: Critical Microsoft SharePoint Remote Code Execution Flaw Actively Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Code Execution on Microsoft SharePoint through BDC Deserialization
blogs_trendmicro·2019-09-19·CVSS 9.8
CVE-2019-1257 [CRITICAL] Code Execution on Microsoft SharePoint through BDC Deserialization
## CVE-2019-1257: Code Execution on Microsoft SharePoint Through BDC Deserialization
Discover code execution on Microsoft SharePoint through BDC deserialization.
By: Zero Day Initiative 2019/09/19 Read time: ( words)
Save to Folio
Earlier this year, researcher Markus Wulftange ( @mwulftange ) reported a remote code execution (RCE) vulnerability in Microsoft SharePoint that ended up being patched as CVE-2019-0604 . He wasn’t done. In September, three additional SharePoint RCEs reported by Markus were addressed by Microsoft: CVE-2019-1295 , CVE-2019-1296 , and CVE-2019-1257 . This blog looks at that last CVE, also known as ZDI-19-812 , in greater detail. This bug affects all supported versions of SharePoint and received Microsoft’s highest Exploit Index rating, which means they expect to
Trendmicro
Code Execution on Microsoft SharePoint through BDC Deserialization
blogs_trendmicro·2019-09-19·CVSS 9.8
CVE-2019-1257 [CRITICAL] Code Execution on Microsoft SharePoint through BDC Deserialization
# CVE-2019-1257: Code Execution on Microsoft SharePoint Through BDC Deserialization
Discover code execution on Microsoft SharePoint through BDC deserialization.
By: Zero Day Initiative
2019/09/19
Read time: ( words)
Save to Folio
Earlier this year, researcher Markus Wulftange (@mwulftange) reported a remote code execution (RCE) vulnerability in Microsoft SharePoint that ended up being patched as CVE-2019-0604. He wasn’t done. In September, three additional SharePoint RCEs reported by Markus were addressed by Microsoft: CVE-2019-1295, CVE-2019-1296, and CVE-2019-1257. This blog looks at that last CVE, also known as ZDI-19-812, in greater detail. This bug affects all supported versions of SharePoint and received Microsoft’s highest Exploit Index rating, which means they expect to see ac
Securelist
APT trends report Q2 2019
blogs_securelist·2019-08-01
APT trends report Q2 2019
Table of Contents
- The most remarkable findings
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For two years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They aim to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q2 2019.
Readers who would like to learn more abou
Securelist
APT trends report Q2 2019
blogs_securelist·2019-08-01
APT trends report Q2 2019
Table of Contents
The most remarkable findings
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For two years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They aim to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q2 2019.
Readers who would like to learn more about our intel
Checkpoint
3rd June – Threat Intelligence Bulletin
blogs_checkpoint·2019-06-03
CVE-2019-0708 3rd June – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd June – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 3rd June 2019, please download our Threat Intelligence Bulletin
TOP ATTACKS AND BREACHES
Around 855 million of insurance-related documents have been leaked online after the US real-estate insurance company First American Financial Corp. accidentally left the documents unsecured on their website. The leaked data, dated back to 2003, included bank account numbers, mortgage and tax records, social security numbers
Unit42
Emissary Panda Attacks Middle East Government SharePoint Servers
blogs_unit42·2019-05-28·CVSS 8.8
CVE-2019-0604 [HIGH] Emissary Panda Attacks Middle East Government SharePoint Servers
Threat Research Center
Threat Actor Groups
Nation-State Cyberattacks
## Emissary Panda Attacks Middle East Government SharePoint Servers
Robert Falcone
Tom Lancaster
Published: May 28, 2019
Malware
Nation-State Cyberattacks
Threat Actor Groups
Threat Research
APT27
Bronze Union
China Chopper
CVE-2019-0604
DLL Sideloading
Emissary Panda
ETERNALBLUE
HyperBro
Lucky Mouse
MS17-010
TG-3390
Webshell
Executive Summary
In April 2019, Unit 42 observed the Emissary Panda (AKA APT27, TG-3390, Bronze Union, Lucky Mouse) threat group installing webshells on SharePoint servers to compromise Government Organizations of two different countries in the Middle East. We believe the adversary exploited a recently patched vulnerability in Microsoft SharePoint tracked by CVE-2019-0604 ,
Unit42
Emissary Panda Attacks Middle East Government SharePoint Servers
blogs_unit42·2019-05-28·CVSS 8.8
CVE-2019-0604 [HIGH] Emissary Panda Attacks Middle East Government SharePoint Servers
Executive Summary
In April 2019, Unit 42 observed the Emissary Panda (AKA APT27, TG-3390, Bronze Union, Lucky Mouse) threat group installing webshells on SharePoint servers to compromise Government Organizations of two different countries in the Middle East. We believe the adversary exploited a recently patched vulnerability in Microsoft SharePoint tracked by CVE-2019-0604, which is a remote code execution vulnerability used to compromise the server and eventually install a webshell. The actors uploaded a variety of tools that they used to perform additional activities on the compromised network, such as dumping credentials, as well as locating and pivoting to additional systems on the network. Of particular note is their use of tools to identify systems vulnerable to CVE-2017-0144, which
Qualys
February 2019 Patch Tuesday – 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns
blogs_qualys·2019-02-12·CVSS 8.8
[HIGH] February 2019 Patch Tuesday – 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns
This month’s Patch Tuesday is very large, with 74 vulns being addressed of which 20 are labeled as critical. Fifteen of these critical vulns are in the Scripting Engine and browsers, with the remainder being GDI+, SharePoint, and DHCP. Microsoft also issued an Advisory for an Exchange 0-day, along with a patch for one of the two reported vulns. Adobe also released updates for Acrobat/Reader, Flash, Coldfusion, and Creative Cloud.
## Workstation Patches
Browser, Scripting Engine, and GDI+ patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Exchange
In late January, a 0-day exploit was announced for Microsoft Exchange.
Qualys
February 2019 Patch Tuesday - 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns | Qualys
blogs_qualys·2019-02-12·CVSS 8.8
[HIGH] February 2019 Patch Tuesday - 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns | Qualys
This month’s Patch Tuesday is very large, with 74 vulns being addressed of which 20 are labeled as critical. Fifteen of these critical vulns are in the Scripting Engine and browsers, with the remainder being GDI+, SharePoint, and DHCP. Microsoft also issued an Advisory for an Exchange 0-day, along with a patch for one of the two reported vulns. Adobe also released updates for Acrobat/Reader, Flash, Coldfusion, and Creative Cloud.
### Workstation Patches
Browser, Scripting Engine, and GDI+ patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Exchange
In late January, a 0-day exploit was announced for Microsoft Exchange
Threat Intel
VOID MANTICORE (VOID MANTICORE, COBALT MYSTIQUE, Handala Hack)
threat_intel
CVE-2019-0604 VOID MANTICORE (VOID MANTICORE, COBALT MYSTIQUE, Handala Hack)
# Threat Actor Profile: VOID MANTICORE
ATT&CK ID: G1055
Also known as: VOID MANTICORE, COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm
Suspected origin: Iran
## Overview
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) VOID MANTICORE conducts destructive cyber operations, combining wiper attacks wit
Recorded Future
Analyzing the Threat of Ransomware Attacks Against US Elections
blogs_recorded_future
Analyzing the Threat of Ransomware Attacks Against US Elections
## Analyzing the Threat of Ransomware Attacks Against US Elections
Note : Prior to this report being publicly released, Recorded Future sent a copy of the report to all relevant state agencies, as well as CISA, for review. Many thanks go out to election experts at the local, state, and federal level who were willing to offer candid feedback on early drafts of this report, and a special thanks to Ryan Macias, SME — Election Technology & Security, for his comprehensive feedback.
Click here to download the complete report as a PDF.
The threat of a ransomware attack against elections in the United States has been a growing concern within the government and the private sector . We already know that threat actors managed to infiltrate the networks of election offices in multiple states , and
Recorded Future
Analyzing the Threat of Ransomware Attacks Against US Elections
blogs_recorded_future
Analyzing the Threat of Ransomware Attacks Against US Elections
# Analyzing the Threat of Ransomware Attacks Against US Elections
Note: Prior to this report being publicly released, Recorded Future sent a copy of the report to all relevant state agencies, as well as CISA, for review. Many thanks go out to election experts at the local, state, and federal level who were willing to offer candid feedback on early drafts of this report, and a special thanks to Ryan Macias, SME — Election Technology & Security, for his comprehensive feedback.
Click here to download the complete report as a PDF.
The threat of a ransomware attack against elections in the United States has been a growing concern within the government and the private sector. We already know that threat actors managed to infiltrate the networks of election offices in multiple states, and acco
Threat Intel
Threat Group-3390 (Threat Group-3390, Earth Smilodon, TG-3390)
threat_intel·CVSS 9.8
[CRITICAL] Threat Group-3390 (Threat Group-3390, Earth Smilodon, TG-3390)
# Threat Actor Profile: Threat Group-3390
ATT&CK ID: G0027
Also known as: Threat Group-3390, Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon
Suspected origin: China
## Overview
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)
## Techniques (TTPs)
### Resource Development
- T1608.001 Upload Malware
Usage: Threat Group-3390 has hosted mal
HackerOne
Remote Code Execution - Unauthenticated Remote Command Injection (via Microsoft SharePoint CVE-2019-0604)
hackerone·2020-05-11·CVSS 9.8
CVE-2019-0604 [CRITICAL] Remote Code Execution - Unauthenticated Remote Command Injection (via Microsoft SharePoint CVE-2019-0604)
Remote Code Execution - Unauthenticated Remote Command Injection (via Microsoft SharePoint CVE-2019-0604)
**Summary:**
Microsoft recently released a patch for CVE-2019-0604. This vulnerability is caused by the Microsoft SharePoint application deserializing untrusted data from a user.
This means an attacker can send a specially crafted/encoded parameter to a Microsoft SharePoint URL, and it will allow Remote Code Execution or Command Injection on the server.
This is an in-depth blog post about the vulnerability.
https://www.thezdi.com/blog/2019/3/13/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability
The ████ SharePoint site suffers from this vulnerability. The URL for the main site is: https://████/███████/OrgStruct/StandingGroups/Pages/default.aspx
**Description:**
##
HackerOne
Store Development Resource Center was vulnerable to a Remote Code Execution - Unauthenticated Remote Command Injection (CVE-2019-0604)
hackerone·2019-12-12·CVSS 9.8
CVE-2019-0604 [CRITICAL] Store Development Resource Center was vulnerable to a Remote Code Execution - Unauthenticated Remote Command Injection (CVE-2019-0604)
Store Development Resource Center was vulnerable to a Remote Code Execution - Unauthenticated Remote Command Injection (CVE-2019-0604)
l00ph0le discovered an endpoint on the Store Development Resource Center site at https://sdrc.starbucks.com/_layouts/15/picker.aspx was vulnerable to a deserialization RCE in Microsoft Sharepoint per CVE-2019-0604.
@l00ph0le — thank you for reporting this vulnerability, your patience while we applied the patch and for confirming the resolution.
arXiv
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
arxiv_fulltext·2022-02-03
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
Octavian Suciu,
Connor Nelson ,
Zhuoer Lyu ,
Tiffany Bao ,
Tudor Dumitras
University of Maryland, College Park
State University
comment
\@IEEEpubidpullup6.5
Network and Distributed Systems Security (NDSS) Symposium 2020
23-26 February 2020, San Diego, CA, USA
ISBN 1-891562-61-4
https://dx.doi.org/10.14722/ndss.2020.23xxx
www.ndss-symposium.org
[ ]
comment
empty
## Abstract
Assessing the exploitability of software vulnerabilities at the time of disclosure is difficult and error-prone, as features extracted via technical analysis by existing metrics are poor predictors for exploit development.
Moreover, exploitability assessments suffer from a class bias because ``not exploitable'' labels could be inaccurate.
To overcome these challenges, we propose a new metric, called Expecte
arXiv
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
arxiv_fulltext·2021-02-10·CVSS 8.8
CVE-2017-11882 [HIGH] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Top 10 Most Exploited Vulnerabilities 2016-2019
(https://us-cert.cisa.gov/ncas/alerts/aa20-133a)
.83fcdec8a329824466f140a2e6cdfeec473a9ee2 .0
longtable[]@lllllll@
& CVSS Score & Number of Tactics & Number of Techniques &
Number of CAPECs & Number of CWEs & Number of CPEs
CVE-2017-11882 & 8.55 & 0 & 0 & 12 & 1 & 4
CVE-2017-0199 & 8.55 & 0 & 0 & 0 & 0 & 9
CVE-2017-5638 & 10.0 & 1 & 3 & 51 & 1 & 53
CVE-2012-0158 & 9.3 & 0 & 0 & 3 & 1 & 29
CVE-2019-0604 & 8.65 & 1 & 3 & 51 & 1 & 4
CVE-2017-0143 & 0.0 (not listed in BRON but NVD says high severity)
& 0 & 0 & 0 & 0 & 0
CVE-2018-4878 & 8.65 & 0 & 0 & 0 & 1 & 3
CVE-2017-8759 & 8.55 & 1 & 3 & 51 & 1 & 8
CVE-2015-1641 & 9.3 & 0 & 0 & 0 & 1 & 11
CVE-2018-7600 & 8.65 & 1 & 3 & 51 & 1 & 4
longtable
4 out of Top 10 Vulnerabilities share the follow
http://www.securityfocus.com/bid/106914https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604http://www.securityfocus.com/bid/106914https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0604
2019-03-05
Published
2021-11-03
Added to CISA KEV
Exploited in the wild