CVE-2019-0604
Summary
| CVE | CVE-2019-0604 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-05 23:29:00 UTC |
| Updated | 2019-12-13 15:17:00 UTC |
| Description | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. |
Risk And Classification
EPSS: 0.944410000 probability, percentile 0.999900000 (date 2026-04-02)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Known
Problem Types: CWE-20
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | SharePoint |
| Name | Microsoft SharePoint Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-0604 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Foundation | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Foundation | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2019 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2019 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft SharePoint Server CVE-2019-0604 Remote Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150496 Microsoft SharePoint Server Multiple Vulnerabilities