Umbra Wiki cve cve/CVE-2020-1147
Back to wiki

CVE-2020-1147 — Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2020-1147

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product .NET Framework, SharePoint, Visual Studio
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-1147

Weakness behind it

CISA has not recorded a CWE for this entry, so the CVE → CWE → CAPEC → ATT&CK chain cannot be walked from here. That is a gap in the catalogue, not evidence the vulnerability has no weakness class — check the NVD record below.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-1147
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →

Related pages