vulnti.work

Microsoft SharePoint Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2019-0604
First seen2021-11-03 00:00 UTC
Disclosed2021-11-03 00:00 UTC
Last updated2026-07-18 08:00 UTC
Channel statuspending_review

Summary

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Microsoft:SharePoint

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV