{"cveID":"CVE-2019-0604","vendorProject":"Microsoft","product":"SharePoint","vulnerabilityName":"Microsoft SharePoint Remote Code Execution Vulnerability","dateAdded":"2021-11-03","shortDescription":"Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2019-0604","cwes":["CWE-20"],"year":2019,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2019-0604","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"CVE-2019-0604 is a vulnerability in an XML deserialization component within Microsoft SharePoint allowed remote attackers to typically install webshell malware to vulnerable hosts. ","references":["https://www.zdnet.com/article/fbi-nation-state-actors-have-breached-two-us-municipalities/","https://ociso.ucla.edu/news/cyber-actors-exploit-sharepoint-vulnerability-gain-access-unprotected-networks","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-0604","technique":"T1003","technique_name_at_mapping":"OS Credential Dumping","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"CVE-2019-0604 is a vulnerability in an XML deserialization component within Microsoft SharePoint allowed remote attackers to typically install webshell malware to vulnerable hosts. ","references":["https://www.zdnet.com/article/fbi-nation-state-actors-have-breached-two-us-municipalities/","https://ociso.ucla.edu/news/cyber-actors-exploit-sharepoint-vulnerability-gain-access-unprotected-networks","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-0604","technique":"T1041","technique_name_at_mapping":"Exfiltration Over C2 Channel","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2019-0604 is a vulnerability in an XML deserialization component within Microsoft SharePoint allowed remote attackers to typically install webshell malware to vulnerable hosts. ","references":["https://www.zdnet.com/article/fbi-nation-state-actors-have-breached-two-us-municipalities/","https://ociso.ucla.edu/news/cyber-actors-exploit-sharepoint-vulnerability-gain-access-unprotected-networks","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-0604","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2019-0604 is a vulnerability in an XML deserialization component within Microsoft SharePoint allowed remote attackers to typically install webshell malware to vulnerable hosts. ","references":["https://www.zdnet.com/article/fbi-nation-state-actors-have-breached-two-us-municipalities/","https://ociso.ucla.edu/news/cyber-actors-exploit-sharepoint-vulnerability-gain-access-unprotected-networks","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-0604","technique":"T1608.001","technique_name_at_mapping":"Upload Malware","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2019-0604 is a vulnerability in an XML deserialization component within Microsoft SharePoint allowed remote attackers to typically install webshell malware to vulnerable hosts. ","references":["https://www.zdnet.com/article/fbi-nation-state-actors-have-breached-two-us-municipalities/","https://ociso.ucla.edu/news/cyber-actors-exploit-sharepoint-vulnerability-gain-access-unprotected-networks","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"OS Credential Dumping","name_at_mapping":"OS Credential Dumping","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1041","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over C2 Channel","name_at_mapping":"Exfiltration Over C2 Channel","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":5,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":35,"has_detection_strategy":true},{"id":"T1608.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Upload Malware","name_at_mapping":"Upload Malware","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}