Junglewise Threat Intelligence

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

CVE-2020-1147 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft .NET Framework, Microsoft Visual Studio, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft .NET Framework, SharePoint, and Visual Studio due to improper validation of source markup in XML file input. An attacker can exploit this by providing malicious XML content, leading to code execution during the deserialization process.

Affected products

  • Microsoft .NET Framework
  • Microsoft SharePoint
  • Microsoft Visual Studio

Timeline

  • 2020-07-14: advisory: MSRC security guidance published.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: Publicly disclosed date per advisory metadata.

Related threats