ZeroHour

CVE-2020-0646

KEV PoC mass

XML Injection RCE in Microsoft .NET Framework

CISA: Microsoft .NET Framework Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

Microsoft .NET Framework fails to properly validate input in certain conditions, allowing XML/XOML injection (CWE-91) that leads to remote code execution. Per the CVSS vector, the flaw is exploitable over the network with no authentication and no user interaction, and the public proof-of-concept demonstrates it by injecting crafted XOML into SharePoint workflow definitions. A successful attacker can run arbitrary code in the context of the vulnerable application, with high impact on confidentiality, integrity, and availability. Any organization running affected .NET Framework versions is potentially exposed, with the demonstrated attack path targeting servers running SharePoint or other .NET-based applications that process untrusted input. The vulnerability is being actively exploited: it was added to the CISA KEV on November 3, 2021, and EPSS assigns a 99.2% probability of exploitation within 30 days (top percentile).

What to do: Apply Microsoft's January 2020 (or later) .NET Framework security updates on all Windows systems, prioritizing internet-facing servers — especially SharePoint — in line with the CISA KEV required action. As interim mitigation, restrict and monitor untrusted input reaching .NET/SharePoint workflow (XOML) processing on exposed servers. Inventory hosts for outdated .NET Framework versions and verify the January 2020 cumulative updates are installed.

Affected
Microsoft .NET Frameworkspecific affected version ranges not enumerated in the source data; addressed in Microsoft's January 2020 security updates
Estimated exposure
masshundreds of millions of Windows devices (ubiquitous OS component); tens of thousands of internet-exposed SharePoint servers as the demonstrated attack path — .NET Framework ships with virtually all Windows installations (over a billion active Windows devices), and public internet scans show tens of thousands of exposed SharePoint servers, the application used in the public PoC.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft .NET Framework
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
.net framework
Weakness
CWE-91
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news