cve-2019-0604
CRITICAL CVSS 9.8 cisa_known_exploited
Description
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
Timeline
- Published
- 2021-11-03
- Last Modified
- 2021-11-03
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.8,
"datePublished": "2021-11-03",
"dateUpdated": "2021-11-03",
"description": "Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.",
"dueDate": "2022-05-03",
"id": "CVE-2019-0604",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-0604",
"product": "SharePoint",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "Microsoft SharePoint Remote Code Execution Vulnerability",
"vendor": "Microsoft"
}
Enrichment data
Aggregated bundle (all enrichments)