SecPod

Learn Search

Search across all Learn content

← Back to Security Research
ALERT: Remote Code Execution Vulnerability in Microsoft SharePoint (CVE-2019-0604)

ALERT: Remote Code Execution Vulnerability in Microsoft SharePoint (CVE-2019-0604)

May 8, 2019By Vidita V Koushik2 min read

Image Credit: threatpost.com

A remote code execution vulnerability exists in Microsoft SharePoint. This vulnerability, tracked as CVE-2019-0604 was reported by Markus Wulftange. This vulnerability was rated critical and can be mitigated using a patch management tool. However, no exploits were at the time of release.

Now, a number of organizations reported active exploits of this remote code execution vulnerability in regions of Canada and Middle East where the initial infection achieves using a China Chopper web-shell. AlienLabs found malware samples (https://pastebin.com/bUFPhucz) that could be an earlier version of the malware which is capable of executing commands and also uploading or downloading files. Reports indicate that this malware linked to FIN7 group. However, a patch management solution can patch the vulnerabilities.

Microsoft explains that this vulnerability exists due to the failure of the software to check the source markup of an application package which allows an attacker to execute arbitrary code on the affected machine. But also requires that a user uploads a specially crafted SharePoint application package for the exploitation to be successful.

Markus explained in a detailed blog that this vulnerability can exploit using the EntityInstanceIdEncoder type from the Microsoft.SharePoint.Portal.dll with the Picker.aspx.

Affected Products

The products affected by this vulnerability are :

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2010 Service Pack 2
  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server 2010 Service Pack 2
  • Microsoft SharePoint Server 2013 Service Pack 1
  • Microsoft SharePoint Server 2019

Impact:

However, an attacker can run arbitrary code in the context of the affected application.

Solution:

Please refer to this KB article.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026