CVE-2020-1147

unknown KEV
Published 2022-05-24 · Modified 2021-11-03
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H
CVSS v2
VIR risk
1.5

Description

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

CISA KEV

Vendor
Microsoft
Product
.NET Framework, SharePoint, Visual Studio
Due date
2022-05-03

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2020-1147

Exploits

Package impact

EcosystemPackageVulnerableFixed
nuget NuGetMicrosoft.NETCore.App>=2.1.0,<2.1.202.1.20
nuget NuGetMicrosoft.NETCore.App.Runtime.linux-arm>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.linux-arm64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.linux-musl-arm64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.linux-musl-x64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.linux-x64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.osx-x64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.rhel.6-x64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.win-arm>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.win-arm64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.win-x64>=3.1.0,<3.1.63.1.6
nuget NuGetMicrosoft.NETCore.App.Runtime.win-x86>=3.1.0,<3.1.63.1.6

References

Verify integrity in audit chain (admin only). AS-IS.