6.8
CVSSv2

CVE-2020-1147

Published: 14/07/2020 Updated: 12/07/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net core 2.1

microsoft .net core 3.1

microsoft .net_framework 2.0

microsoft .net_framework 3.0

microsoft .net_framework 3.5

microsoft .net_framework 4.6.2

microsoft .net_framework 4.7

microsoft .net_framework 4.7.1

microsoft .net_framework 4.7.2

microsoft .net_framework 4.6.1

microsoft .net_framework 4.6

microsoft .net_framework 4.8

microsoft .net_framework 3.5.1

microsoft .net_framework 4.5.2

microsoft sharepoint server 2010

microsoft sharepoint enterprise server 2016

microsoft sharepoint enterprise server 2013

microsoft sharepoint server 2019

microsoft visual studio 2019

microsoft visual studio 2017

Vendor Advisories

Synopsis Critical: NET Core 31 on Red Hat Enterprise Linux security and bugfix update Type/Severity Security Advisory: Critical Topic An update for rh-dotnet31-dotnet is now available for NET Core on Red Hat Enterprise LinuxRed Hat Product Security has rated this update as having a security impact of Cr ...
Synopsis Critical: NET Core 31 security and bugfix update Type/Severity Security Advisory: Critical Topic An update for NET Core 31 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring Syste ...
Synopsis Critical: NET Core 21 on Red Hat Enterprise Linux security and bugfix update Type/Severity Security Advisory: Critical Topic An update for rh-dotnet21-dotnet is now available for NET Core on Red Hat Enterprise LinuxRed Hat Product Security has rated this update as having a security impact of Cr ...
Synopsis Critical: NET Core security and bugfix update Type/Severity Security Advisory: Critical Topic An update for NET Core is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) ...
Synopsis Critical: NET Core security and bugfix update Type/Severity Security Advisory: Critical Topic An update for NET Core is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) ...
Synopsis Critical: NET Core security update Type/Severity Security Advisory: Critical Topic An update for NET Core is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerabil ...

Exploits

Microsoft SharePoint Server 2019 remote code execution exploit ...
Microsoft SharePoint Server 2019 remote code execution exploit ...

Recent Articles

Old-school security hole perfect for worms and remote hijackings found lurking in Windows Server DNS code
The Register • Shaun Nichols in San Francisco • 15 Jul 2020

You'll want to patch that – and all these other bugs fixed by Microsoft, Oracle, Adobe, VMware, SAP, Google So kind of SAP NetWeaver to hand out admin accounts to anyone who can reach it. You'll want to patch this

Mega Patch Tuesday Microsoft on Tuesday patched a wormable hole in its Windows Server software that can be exploited remotely to completely commandeer the machine without any authorization. It was one of hundreds of security bugs squashed today by Redmond along with Oracle, Adobe, VMware, SAP and Google. Microsoft emitted fixes for 123 vulnerabilities in this month's Patch Tuesday batch. Some 18 of those CVE-listed security flaws are considered critical, meaning remote code execution (RCE) is po...