Umbra Wiki cve cve/CVE-2020-1147
Back to wiki

CVE-2020-1147 — Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2020-1147

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product .NET Framework, SharePoint, Visual Studio
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-1147

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-1147
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog