Medium severity6.5NVD Advisory· Published Nov 12, 2019· Updated Jun 17, 2026
CVE-2019-1443
CVE-2019-1443
Description
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Affected products
8cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 2016
- (no CPE)range: 2019
cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*
- (no CPE)range: 2010 Service Pack 2
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1443nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.