FBI Alert AC-000113-TT: Unidentified Cyber Actors Exploit SharePoint Vulnerability to Gain Access to Unprotected Networks

FBI Alert AC-000113-TT: Unidentified Cyber Actors Exploit SharePoint Vulnerability to Gain Access to Unprotected Networks

TLP Green
January 8, 2020

 

 

 

Since June 2019, unidentified cyber actors have used a SharePoint vulnerability, CVE-2019-0604, to exploit notable US entities. Following a widespread scanning for CVE-2019-0604 in May, June, and October 2019, respectively, cyber actors compromised the network of two identified US municipalities using CVE-2019-0604. Malicious activities included exfiltration of user information, escalation of administrative privileges, and the dropping of webshells for remote/backdoor persistent access.