Website Security & Threat Management
Stopping SharePoint’s CVE-2019-0604

Stopping SharePoint’s CVE-2019-0604

5/28/2019 · Georgie Yoxall

What this post added

This post details Cloudflare's rapid response to CVE-2019-0604, a critical RCE vulnerability in Microsoft SharePoint. It describes the process of analyzing the vulnerability, identifying its exploitable paths (including unauthenticated external access), deploying a firewall rule (100157) in log mode for traffic analysis, and subsequently enabling default block mode to protect customers before a stable patch was widely adopted. The post also analyzes the observed reconnaissance probes and exploit attempts, highlighting the targeted nature of attacks against enterprise businesses and the importance of timely patching and access management solutions like Cloudflare Access.

Read the original post ↗