ZeroHour

CVE-2020-1147

KEV PoC ×4mass

XML Markup RCE in Microsoft .NET Framework, SharePoint, and Visual Studio

CISA: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
94%p100
Published
()
KEV added
AI analysis

CVE-2020-1147 is a remote code execution flaw that exists in Microsoft .NET Framework, .NET Core, SharePoint Enterprise Server, SharePoint Server, Visual Studio 2017, and Visual Studio 2019 when the software fails to check the source markup of XML file input. It is triggered when an application parses attacker-controlled XML — public proofs-of-concept demonstrate exploitation through SharePoint's DataSet/DataTable deserialization, allowing an attacker to run arbitrary code in the context of the affected application or service. An attacker who successfully exploits the flaw gains code execution with the privileges of the parsing process, which on SharePoint servers typically means compromise of a widely used business platform. Organizations running affected .NET Framework, .NET Core, SharePoint, or Visual Studio deployments are affected. Exploitation is confirmed: public PoCs were released around the July 2020 Patch Tuesday fixes, the flaw was added to CISA's Known Exploited Vulnerabilities catalog in November 2021, and news reports describe the Storm-2603 group deploying ransomware on exploited SharePoint servers.

What to do: Apply the July 2020 Microsoft security updates for .NET Framework, .NET Core, SharePoint, and Visual Studio, as required by CISA's KEV catalog entry. Prioritize internet-facing SharePoint servers, and hunt for signs of exploitation there given reports of Storm-2603 deploying ransomware on exploited SharePoint servers. Until patched, restrict untrusted XML input handling and limit exposure of SharePoint and other affected services to the internet.

Affected
Microsoft .NET Framework
Microsoft .NET Core
Microsoft SharePoint Enterprise Serversupported versions fixed in July 2020 security updates; PoCs target SharePoint Server 2019
Microsoft SharePoint Serversupported versions fixed in July 2020 security updates; public PoCs target SharePoint Server 2019
Microsoft Visual Studio 2017supported releases fixed in July 2020 security updates
Microsoft Visual Studio 2019supported releases fixed in July 2020 security updates
Estimated exposure
masshundreds of millions of Windows devices with .NET Framework installed, plus tens of thousands of SharePoint deployments (order of magnitude estimate) — .NET Framework and .NET Core ship with or are deployed on essentially every Windows machine, making the potential installed base in the hundreds of millions of devices, while public internet scans and SharePoint's ubiquity as an enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft .NET Framework, SharePoint, Visual Studio
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
.net core, .net framework, sharepoint enterprise server, sharepoint server, visual studio 2017, visual studio 2019
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news