cbcvebase.
CVE-2019-0952
published 2019-05-16

CVE-2019-0952: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka…

PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
9.55%
94.9th percentile
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_foundation
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by an authenticated user creating and invoking a specially crafted page on an affected Microsoft SharePoint Server — monitor for unusual page creation and invocation by authenticated users in SharePoint audit logs.
  • The attack abuses unsafe ASP.Net web controls not properly filtered by SharePoint — look for suspicious ASP.Net control markup or web part content in SharePoint pages/content.
  • Successful exploitation results in code execution in the context of the SharePoint application pool process — monitor for anomalous child processes spawned from the SharePoint application pool worker process (w3wp.exe).
  • The Preview Pane is NOT an attack vector — focus detection on full page load/render events rather than previewPane activity.
  • ·Exploitation requires an authenticated attacker — unauthenticated access alone is insufficient to trigger this vulnerability.
  • ·As of the advisory, the vulnerability had not been publicly disclosed or exploited in the wild, reducing immediate threat urgency but not eliminating it.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.