CVE-2020-1147
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
- Affected products
- .Net Framework, Alt Linux, Centos, Sharepoint Server, Red Hat, Visual Studio
- Microsoft .net Core
- = 2.1, 3.1
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 94.3% (100th percentile)
- NVD status
- Analyzed
- Published
- 2020-07-14
CVE-2020-1147 at NVD
9 known exploits for CVE-2020-1147
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft SharePoint Server 2019 - Remote Code Execution Exploit (2)
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
Microsoft SharePoint Server 2019 Remote Code Execution
Microsoft SharePoint Server 2019 - Remote Code Execution Exploit
Microsoft SharePoint Server 2019 - Remote Code Execution
Microsoft SharePoint Server 2019 Remote Code Execution
SharePoint DataSet / DataTable Deserialization Exploit
SharePoint DataSet / DataTable Deserialization
SharePoint DataSet / DataTable Deserialization