CVE-2020-1147 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 94% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 93.97% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2020-07-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Microsoft / .NET Framework, SharePoint, Visual Studio |
| Ransomware use | none reported |
Affected (14)
| Vendor | Product |
|---|---|
| microsoft | .net core |
| microsoft | .net framework |
| microsoft | sharepoint enterprise server |
| microsoft | sharepoint server |
| microsoft | visual studio 2017 |
| microsoft | visual studio 2019 |
| microsoft | windows 10 |
| microsoft | windows 7 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
| microsoft | windows server 2019 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft SharePoint Server 2019 - Remote Code Execution (2) | 2021-07-23 |
| exploit-db | Microsoft SharePoint Server 2019 - Remote Code Execution | 2020-08-17 |
References
- http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.html
- http://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147
- https://www.exploitalert.com/view-details.html?id=35992
- http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.html
- http://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147
- https://www.exploitalert.com/view-details.html?id=35992
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1147
→ the Explorer · watch your stack · NVD