cbcvebase.
CVE-2019-0604
published 2019-03-05

CVE-2019-0604: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.91%
100.0th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

Affected

14 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_foundation
microsoftmicrosoft_sharepoint_server
microsoftmicrosoft_sharepoint_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2010_service_pack_2
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2010_service_pack_2
msrcmicrosoft_sharepoint_server_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019

Detection & IOCsextracted from sources · hover to see the quote

hashb814532d73c7e5ffd1a2533adc6cfcf8
hashdc8e7b7de41cac9ded920c41b272c885e1aec279
hash05108ac3c3d708977f2d679bfa6d2eaf63b371e66428018a68efce4b6a45b4b4
hash708544104809ef2776ddc56e04d27ab1
hashf0fb0f7553390f203669e53abc16b15e729e5c6f
hashb560c3b9b672f42a005bdeae79eb91dfb0dec8dc04bea51f38731692bc995688
hash0eebeef32a8f676a1717f134f114c8bd
hash4c3b262b4134366ad0a67b1a2d6378da428d712b
hash7d6812947e7eafa8a4cce84b531f8077f7434dbed4ccdaca64225d1b6a0e8604
hash5001ef50c7e869253a7c152a638eab8a
pathpicker.aspx
  • CVE-2019-0604 exploitation targets the DecodeEntityInstanceId method within Microsoft.SharePoint.dll via a specially crafted web request to picker.aspx; monitor for anomalous POST requests to this endpoint on SharePoint servers.
  • Post-exploitation activity following CVE-2019-0604 exploitation includes webshell (primarily China Chopper) installation on SharePoint servers; hunt for China Chopper webshell artifacts on SharePoint hosts.
  • Post-exploitation credential dumping via Mimikatz follows CVE-2019-0604 webshell deployment; monitor for Mimikatz execution on SharePoint servers and lateral movement activity.
  • VOID MANTICORE (Iranian MOIS-linked threat actor) has exploited CVE-2019-0604 for initial access to SharePoint servers; correlate SharePoint exploitation with subsequent wiper/destructive payload deployment.
  • Apply Qualys QID 110330 to scan for CVE-2019-0604 exposure; patch with KB4462199, KB4462202, KB4462143, KB4462184, KB4461630, KB4462211 for applicable SharePoint versions.
  • ·CVE-2019-0604 exploitation requires the attacker to have special/authenticated rights on the SharePoint server to execute code in the context of the SharePoint application pool and farm account.
  • ·Successful exploitation allows arbitrary code execution in the context of the SharePoint application pool and the SharePoint server farm account, not SYSTEM-level by default.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.