Back

CVE-2019-0604

CRITICAL CISA KEV

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

Published: Mar 5, 2019 Modified: Jun 17, 2026
CWE-20 CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
microsoft sharepoint_enterprise_server 2016
microsoft sharepoint_foundation 2013
microsoft sharepoint_server 2010
microsoft sharepoint_server 2019

GitHub Security Advisory GHSA-6mr5-xh3f-7vqm

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 99.83%

Top 0% most likely to be exploited

Threat Score 99.1 / 100

CISA Known Exploited

Date Added: 2021-11-03
Due Date: 2022-05-03
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub