High severity8.8NVD Advisory· Published May 16, 2019· Updated Jun 17, 2026
CVE-2019-0952
CVE-2019-0952
Description
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Affected products
5cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 2016
cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*
- (no CPE)range: 2013 Service Pack 1
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0952nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.