CVE-2020-1147

HIGHCVSS 7.8/10Actively ExploitedEPSS 94.24%

Last modified

CVE-2020-1147 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.. CISA has confirmed active exploitation in the wild. EPSS estimates a 94.24% chance of exploitation in the next 30 days.

Description

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
94.24%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Affected Software

VendorProductVersionsUpdate
Microsoft.Net Core2.1
Microsoft.Net Core3.1
Microsoft.Net Framework2.0Sp2
Microsoft.Net Framework3.0Sp2
Microsoft.Net Framework3.5
Microsoft.Net Framework4.6.2
Microsoft.Net Framework4.7
Microsoft.Net Framework4.7.1
Microsoft.Net Framework4.7.2
Microsoft.Net Framework4.6
Microsoft.Net Framework4.6.1
Microsoft.Net Framework4.8
Microsoft.Net Framework3.5.1
Microsoft.Net Framework4.5.2
MicrosoftSharepoint Enterprise Server2013Sp1
MicrosoftSharepoint Enterprise Server2016
MicrosoftSharepoint Server2010Sp2
MicrosoftSharepoint Server2019
MicrosoftVisual Studio 2017>= 15.0, <= 15.9
MicrosoftVisual Studio 2019>= 16.0, <= 16.6

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2020-1147?
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
How severe is CVE-2020-1147?
CVE-2020-1147 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 94.24% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2020-1147?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-1147?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST