Sploitus

Exploit for Microsoft SharePoint Picker.aspx deserialization vulnerability

saint Β· 2020-03-03

Exploit Code

MARKDOWN26 lines
## https://sploitus.com/exploit?id=SAINT:1AF7483E5B4DB373D9449DD910472EA5
Added: 03/03/2020  
CVE: [CVE-2019-0604](<https://vulners.com/cve/CVE-2019-0604>)  
BID: [106914](<http://www.securityfocus.com/bid/106914>)  


### Background

[Microsoft SharePoint](<https://products.office.com/en-us/sharepoint/collaboration>) is a tool for management and automation of business processes, as well as a platform for social networking. 

### Problem

A deserialization vulnerability in Microsoft SharePoint allows remote attackers to execute arbitrary commands by sending a specially crafted request to the `**Picker.aspx**` resource. 

### Resolution

Apply the appropriate update referenced in Microsoft advisory [CVE-2019-0604](<https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604>). 

### References

<https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604>  


### Platforms

Windows