CVE-2019-1443
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Se presenta una vulnerabilidad de divulgación de información en Microsoft SharePoint cuando un atacante carga un archivo especialmente diseñado en el servidor de SharePoint. Un atacante autenticado que explotó con éxito esta vulnerabilidad podría aprovechar potencialmente la funcionalidad de SharePoint para obtener hashes SMB. La actualización de seguridad aborda la vulnerabilidad al corregir la forma en que SharePoint comprueba el contenido del archivo, también se conoce como "Microsoft SharePoint Information Disclosure Vulnerability".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-26 CVE Reserved
- 2019-11-12 CVE Published
- 2024-03-25 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1443 | 2020-08-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Sharepoint Enterprise Server Search vendor "Microsoft" for product "Sharepoint Enterprise Server" | 2016 Search vendor "Microsoft" for product "Sharepoint Enterprise Server" and version "2016" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Foundation Search vendor "Microsoft" for product "Sharepoint Foundation" | 2010 Search vendor "Microsoft" for product "Sharepoint Foundation" and version "2010" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Foundation Search vendor "Microsoft" for product "Sharepoint Foundation" | 2013 Search vendor "Microsoft" for product "Sharepoint Foundation" and version "2013" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Server Search vendor "Microsoft" for product "Sharepoint Server" | 2019 Search vendor "Microsoft" for product "Sharepoint Server" and version "2019" | - |
Affected
|