CVE-2020-0646
KEV PoC massXML Injection RCE in Microsoft .NET Framework
CISA: Microsoft .NET Framework Remote Code Execution Vulnerability
Microsoft .NET Framework fails to properly validate input in certain conditions, allowing XML/XOML injection (CWE-91) that leads to remote code execution. Per the CVSS vector, the flaw is exploitable over the network with no authentication and no user interaction, and the public proof-of-concept demonstrates it by injecting crafted XOML into SharePoint workflow definitions. A successful attacker can run arbitrary code in the context of the vulnerable application, with high impact on confidentiality, integrity, and availability. Any organization running affected .NET Framework versions is potentially exposed, with the demonstrated attack path targeting servers running SharePoint or other .NET-based applications that process untrusted input. The vulnerability is being actively exploited: it was added to the CISA KEV on November 3, 2021, and EPSS assigns a 99.2% probability of exploitation within 30 days (top percentile).
What to do: Apply Microsoft's January 2020 (or later) .NET Framework security updates on all Windows systems, prioritizing internet-facing servers — especially SharePoint — in line with the CISA KEV required action. As interim mitigation, restrict and monitor untrusted input reaching .NET/SharePoint workflow (XOML) processing on exposed servers. Inventory hosts for outdated .NET Framework versions and verify the January 2020 cumulative updates are installed.
| Microsoft .NET Framework | specific affected version ranges not enumerated in the source data; addressed in Microsoft's January 2020 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
- Affected
- Microsoft .NET Framework
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- .net framework
- Weakness
- CWE-91
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H