CVE-2020-1147
Last modified
CVE-2020-1147 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.. CISA has confirmed active exploitation in the wild. EPSS estimates a 94.24% chance of exploitation in the next 30 days.
Description
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | .Net Core | 2.1 | — |
| Microsoft | .Net Core | 3.1 | — |
| Microsoft | .Net Framework | 2.0 | Sp2 |
| Microsoft | .Net Framework | 3.0 | Sp2 |
| Microsoft | .Net Framework | 3.5 | — |
| Microsoft | .Net Framework | 4.6.2 | — |
| Microsoft | .Net Framework | 4.7 | — |
| Microsoft | .Net Framework | 4.7.1 | — |
| Microsoft | .Net Framework | 4.7.2 | — |
| Microsoft | .Net Framework | 4.6 | — |
| Microsoft | .Net Framework | 4.6.1 | — |
| Microsoft | .Net Framework | 4.8 | — |
| Microsoft | .Net Framework | 3.5.1 | — |
| Microsoft | .Net Framework | 4.5.2 | — |
| Microsoft | Sharepoint Enterprise Server | 2013 | Sp1 |
| Microsoft | Sharepoint Enterprise Server | 2016 | — |
| Microsoft | Sharepoint Server | 2010 | Sp2 |
| Microsoft | Sharepoint Server | 2019 | — |
| Microsoft | Visual Studio 2017 | >= 15.0, <= 15.9 | — |
| Microsoft | Visual Studio 2019 | >= 16.0, <= 16.6 | — |
References
- http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147Patch, Vendor Advisory
- https://www.exploitalert.com/view-details.html?id=35992Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147Patch, Vendor Advisory
- https://www.exploitalert.com/view-details.html?id=35992Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1147US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-1147?
How severe is CVE-2020-1147?
How do I fix CVE-2020-1147?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-11463An issue was discovered in Deskpro before 2019.8.0. The /api…7.5
- CVE-2020-11464An issue was discovered in Deskpro before 2019.8.0. The /api…4.3
- CVE-2020-11465An issue was discovered in Deskpro before 2019.8.0. The /api…8.8
- CVE-2020-11466An issue was discovered in Deskpro before 2019.8.0. The /api…4.3
- CVE-2020-11467An issue was discovered in Deskpro before 2019.8.0. This pro…7.2
- CVE-2020-11469Zoom Client for Meetings through 4.6.8 on macOS copies runwi…7.8
- CVE-2020-11470Zoom Client for Meetings through 4.6.8 on macOS has the disa…3.3
- CVE-2020-11474NCP Secure Enterprise Client before 10.15 r47589 allows a sy…7.8
- CVE-2020-11476Concrete5 before 8.5.3 allows Unrestricted Upload of File wi…7.2
- CVE-2020-1148A spoofing vulnerability exists when Microsoft SharePoint Se…5.4
- CVE-2020-11483NVIDIA DGX servers, all DGX-1 with BMC firmware versions pri…9.8
- CVE-2020-11484NVIDIA DGX servers, all DGX-1 with BMC firmware versions pri…4.9
Are you affected by CVE-2020-1147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
