CVE-2019-0604

CRITICAL KEV RANSOMWARE NUCLEI

Microsoft SharePoint - RCE

Title source: llm

Description

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

Exploits (8)

exploitdb WORKING POC
by Voulnet · pythonremotewindows
https://www.exploit-db.com/exploits/48053
nomisec WORKING POC 133 stars
by linhlhq · poc
https://github.com/linhlhq/CVE-2019-0604
nomisec WORKING POC 101 stars
by k8gege · remote
https://github.com/k8gege/CVE-2019-0604
nomisec WORKING POC 30 stars
by boxhg · poc
https://github.com/boxhg/CVE-2019-0604
nomisec WORKING POC 7 stars
by Gh0st0ne · remote
https://github.com/Gh0st0ne/weaponized-0604
nomisec SCANNER 3 stars
by m5050 · poc
https://github.com/m5050/CVE-2019-0604
nomisec WORKING POC 1 stars
by likekabin · poc
https://github.com/likekabin/CVE-2019-0604_sharepoint_CVE
nomisec WORKING POC
by davidlebr1 · poc
https://github.com/davidlebr1/cve-2019-0604-SP2010-netv3.5

Nuclei Templates (1)

Microsoft SharePoint - Remote Code Execution
CRITICALVERIFIEDby tree-chtsec,pszyszkowski
Shodan: cpe:"cpe:2.3:a:microsoft:sharepoint_server"

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2019-05-10
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-1370
Ransomware Use Confirmed
CWE
CWE-20
Status published
Products (4)
microsoft/sharepoint_enterprise_server 2016
microsoft/sharepoint_foundation 2013 sp1
microsoft/sharepoint_server 2010 sp2
microsoft/sharepoint_server 2019
Published Mar 05, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026