Jul 2020:
CVE-2020-1147 Published on July 14, 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Known Exploited Vulnerability
This Microsoft .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input.
The following remediation steps are recommended / required by May 3, 2022: Apply updates per vendor instructions.
Vulnerability Analysis
CVE-2020-1147 can be exploited with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors. The potential impact of an exploit of this vulnerability is considered to be very high.
Products Associated with CVE-2020-1147
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft SharePoint Enterprise Server:- Version 2016 is affected.
- Version 2013 Service Pack 1 is affected.
- Version 2019 is affected.
- Version 2010 Service Pack 2 is affected.
- Version 16.0 is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version 2.1 is affected.
- Version 3.1 is affected.
- Version Windows 7 for 32-bit Systems Service Pack 1 is affected.
- Version Windows 7 for x64-based Systems Service Pack 1 is affected.
- Version Windows 8.1 for 32-bit systems is affected.
- Version Windows 8.1 for x64-based systems is affected.
- Version Windows RT 8.1 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) is affected.
- Version Windows Server 2012 is affected.
- Version Windows Server 2012 (Server Core installation) is affected.
- Version Windows Server 2012 R2 is affected.
- Version Windows Server 2012 R2 (Server Core installation) is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version 1903 is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version Windows 8.1 for 32-bit systems is affected.
- Version Windows 8.1 for x64-based systems is affected.
- Version Windows Server 2012 is affected.
- Version Windows Server 2012 (Server Core installation) is affected.
- Version Windows Server 2012 R2 is affected.
- Version Windows Server 2012 R2 (Server Core installation) is affected.
- Version Windows 7 for 32-bit Systems Service Pack 1 is affected.
- Version Windows 7 for x64-based Systems Service Pack 1 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 is affected.
- Version Windows 7 for 32-bit Systems Service Pack 1 is affected.
- Version Windows 7 for x64-based Systems Service Pack 1 is affected.
- Version Windows 8.1 for 32-bit systems is affected.
- Version Windows 8.1 for x64-based systems is affected.
- Version Windows RT 8.1 is affected.
- Version Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) is affected.
- Version Windows Server 2012 is affected.
- Version Windows Server 2012 (Server Core installation) is affected.
- Version Windows Server 2012 R2 is affected.
- Version Windows Server 2012 R2 (Server Core installation) is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.