CVE-2020-1147
KEV PoC ×4massXML Markup RCE in Microsoft .NET Framework, SharePoint, and Visual Studio
CISA: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
CVE-2020-1147 is a remote code execution flaw that exists in Microsoft .NET Framework, .NET Core, SharePoint Enterprise Server, SharePoint Server, Visual Studio 2017, and Visual Studio 2019 when the software fails to check the source markup of XML file input. It is triggered when an application parses attacker-controlled XML — public proofs-of-concept demonstrate exploitation through SharePoint's DataSet/DataTable deserialization, allowing an attacker to run arbitrary code in the context of the affected application or service. An attacker who successfully exploits the flaw gains code execution with the privileges of the parsing process, which on SharePoint servers typically means compromise of a widely used business platform. Organizations running affected .NET Framework, .NET Core, SharePoint, or Visual Studio deployments are affected. Exploitation is confirmed: public PoCs were released around the July 2020 Patch Tuesday fixes, the flaw was added to CISA's Known Exploited Vulnerabilities catalog in November 2021, and news reports describe the Storm-2603 group deploying ransomware on exploited SharePoint servers.
What to do: Apply the July 2020 Microsoft security updates for .NET Framework, .NET Core, SharePoint, and Visual Studio, as required by CISA's KEV catalog entry. Prioritize internet-facing SharePoint servers, and hunt for signs of exploitation there given reports of Storm-2603 deploying ransomware on exploited SharePoint servers. Until patched, restrict untrusted XML input handling and limit exposure of SharePoint and other affected services to the internet.
| Microsoft .NET Framework | — |
| Microsoft .NET Core | — |
| Microsoft SharePoint Enterprise Server | supported versions fixed in July 2020 security updates; PoCs target SharePoint Server 2019 |
| Microsoft SharePoint Server | supported versions fixed in July 2020 security updates; public PoCs target SharePoint Server 2019 |
| Microsoft Visual Studio 2017 | supported releases fixed in July 2020 security updates |
| Microsoft Visual Studio 2019 | supported releases fixed in July 2020 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
- Affected
- Microsoft .NET Framework, SharePoint, Visual Studio
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- .net core, .net framework, sharepoint enterprise server, sharepoint server, visual studio 2017, visual studio 2019
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H