CVE-2020-0932
published 2020-04-15CVE-2020-0932: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…
PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
31.21%
98.1th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | business_productivity_servers | — | — |
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/_vti_bin/WebPartPages.asmx
otherSystem.Resources.ResXFileRef
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Microsoft Sharepoint Authenticated WebParts TypeConverter Remote Code Execution (CVE-2020-0932)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/_vti_bin/WebPartPages.asmx"; fast_pattern; http.request_body; content:"|3c|RenderWebPartForEdit"; content:"|3c|property"; content:"System.Resources.ResXFileRef"; reference:url,www.zerodayinitiative.com/blog/2020/4/28/cve-2020-0932-remote-code-execution-on-microsoft-sharepoint-using-typeconverters; reference:cve,2020-0932; classtype:web-application-attack; sid:2063648; rev:1; metadata:affected_product Microsoft_Sharepoint, attack_target Server, tls_state TLSDecrypt, created_at 2025_07_22, cve CVE_2020_0932, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2025_07_22, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
|3c|RenderWebPartForEdit
- →Exploit traffic uses HTTP POST to the SharePoint WebPartPages SOAP endpoint at /_vti_bin/WebPartPages.asmx. The request body contains a RenderWebPartForEdit SOAP call with a property value referencing the System.Resources.ResXFileRef TypeConverter as the malicious payload.
- →The attack requires an authenticated user to interact with the WebPartPages service; monitor for authenticated POST requests to WebPartPages.asmx that include TypeConverter-related class names (e.g., ResXFileRef) in the body.
- →The vulnerability is exploited by uploading a specially crafted SharePoint application package; monitor SharePoint upload events for unexpected or unsigned application packages. ↗
- →Successful exploitation runs arbitrary code in the context of the SharePoint application pool and farm account; alert on unexpected child processes spawned from SharePoint worker processes (w3wp.exe). ↗
- →The Snort/Suricata rule (ET sid:2063648) is tagged for TLS-decrypted traffic (tls_state TLSDecrypt), meaning detection requires TLS inspection at the perimeter or internally.
- ·The Snort/Suricata rule requires TLS decryption to be effective, as SharePoint is typically served over HTTPS. Without TLS inspection, HTTP body content matching (RenderWebPartForEdit, ResXFileRef) will not trigger.
- ·The Preview Pane is NOT an attack vector for this vulnerability; detection should focus on upload and SOAP request paths, not passive rendering. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg3c-qwfq-8wfv: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-0920 [HIGH] GHSA-wg3c-qwfq-8wfv: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
GHSA
GHSA-fmcx-pmpg-q87j: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-0971 [HIGH] CWE-434 GHSA-fmcx-pmpg-q87j: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0974.
GHSA
GHSA-pp7c-m8cf-8vm2: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-0974 [HIGH] GHSA-pp7c-m8cf-8vm2: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971.
GHSA
GHSA-8j3r-p64j-mqh7: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-0929 [HIGH] GHSA-8j3r-p64j-mqh7: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
GHSA
GHSA-p4vm-jv89-q82f: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-0931 [HIGH] GHSA-p4vm-jv89-q82f: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
GHSA
GHSA-f3pr-7rjp-hqhv: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-0932 [HIGH] GHSA-f3pr-7rjp-hqhv: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2020-04-14·CVSS 8.8
CVE-2020-0932 [HIGH] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office
Suricata
ET WEB_SPECIFIC_APPS Microsoft Sharepoint Authenticated WebParts TypeConverter Remote Code Execution (CVE-2020-0932)
suricata·2025-07-22·CVSS 8.8
CVE-2020-0932 [HIGH] ET WEB_SPECIFIC_APPS Microsoft Sharepoint Authenticated WebParts TypeConverter Remote Code Execution (CVE-2020-0932)
ET WEB_SPECIFIC_APPS Microsoft Sharepoint Authenticated WebParts TypeConverter Remote Code Execution (CVE-2020-0932)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Microsoft Sharepoint Authenticated WebParts TypeConverter Remote Code Execution (CVE-2020-0932)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/_vti_bin/WebPartPages.asmx"; fast_pattern; http.request_body; content:"|3c|RenderWebPartForEdit"; content:"|3c|property"; content:"System.Resources.ResXFileRef"; reference:url,www.zerodayinitiative.com/blog/2020/4/28/cve-2020-0932-remote-code-execution-on-microsoft-sharepoint-using-typeconverters; reference:cve,2020-0932; classtype:web-application-attack; sid:2063648; rev:1; metadata:affected_product Microsoft_Sharepoint, attack_targe
No public exploits indexed.
Tenable
Microsoft’s April 2020 Patch Tuesday Addresses 113 CVEs Including Adobe Type Manager Library Zero-Day Flaws (CVE-2020-0938, CVE-2020-1020)
blogs_tenable·2020-04-14·CVSS 7.8
[HIGH] Microsoft’s April 2020 Patch Tuesday Addresses 113 CVEs Including Adobe Type Manager Library Zero-Day Flaws (CVE-2020-0938, CVE-2020-1020)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939, an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities
Trendmicro
April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
blogs_trendmicro·2020-04-14·CVSS 8.8
[HIGH] April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
## April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
Microsoft’s Patch Tuesday for April released fixes for a couple of critical font-related vulnerabilities, like an earlier disclosed one found in Adobe Type Manager Library (atmfd.dll). It also featured patches for vulnerabilities in Microsoft SharePoint and Windows Components.
By: Trend Micro Apr 14, 2020 Read time: ( words)
Save to Folio
Microsoft fixed 113 vulnerabilities in this month’s Patch Tuesday , just two shy of last month’s 115. This continues the streak of longer-than-usual list of patches that began in January . In fact, compared to the same period in 2019, Microsoft fixed 44% more vulnerabilities between January to April of this year.
In this month’s list, 17 were rate
Qualys
April 2020 Patch Tuesday – 113 Vulns, 19 Critical, Zero-Day Patches, SharePoint, Adobe ColdFusion
blogs_qualys·2020-04-14·CVSS 8.4
[HIGH] April 2020 Patch Tuesday – 113 Vulns, 19 Critical, Zero-Day Patches, SharePoint, Adobe ColdFusion
This month’s Microsoft Patch Tuesday addresses 113 vulnerabilities with 19 of them labeled as Critical. The 19 Critical vulnerabilities cover Adobe Font Manager Library (0-day), SharePoint, Hyper-V, Scripting Engines, Media Foundation, Microsoft Graphics, Windows Codecs, and Dynamics Business Central. Adobe released patches today for ColdFusion, After Effects, and Digital Editions.
## Workstation Patches
The Scripting Engine, Adobe Font Manager Library, Media Foundation, Microsoft Graphics, and Windows Codecs patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Windows Kernel Privilege Escalation
While listed as Import
Trendmicro
April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
blogs_trendmicro·2020-04-14·CVSS 8.8
[HIGH] April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
# April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
Microsoft’s Patch Tuesday for April released fixes for a couple of critical font-related vulnerabilities, like an earlier disclosed one found in Adobe Type Manager Library (atmfd.dll). It also featured patches for vulnerabilities in Microsoft SharePoint and Windows Components.
By: Trend Micro
2020/04/14
Read time: ( words)
Save to Folio
Microsoft fixed 113 vulnerabilities in this month’s Patch Tuesday, just two shy of last month’s 115. This continues the streak of longer-than-usual list of patches that began in January. In fact, compared to the same period in 2019, Microsoft fixed 44% more vulnerabilities between January to April of this year.
In this month’s list, 17 were rated as
Qualys
April 2020 Patch Tuesday – 113 Vulns, 19 Critical, Zero-Day Patches, SharePoint, Adobe ColdFusion | Qualys
blogs_qualys·2020-04-14·CVSS 8.4
[HIGH] April 2020 Patch Tuesday – 113 Vulns, 19 Critical, Zero-Day Patches, SharePoint, Adobe ColdFusion | Qualys
This month’s Microsoft Patch Tuesday addresses 113 vulnerabilities with 19 of them labeled as Critical. The 19 Critical vulnerabilities cover Adobe Font Manager Library (0-day), SharePoint, Hyper-V, Scripting Engines, Media Foundation, Microsoft Graphics, Windows Codecs, and Dynamics Business Central. Adobe released patches today for ColdFusion, After Effects, and Digital Editions.
### Workstation Patches
The Scripting Engine, Adobe Font Manager Library, Media Foundation, Microsoft Graphics, and Windows Codecs patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Windows Kernel Privilege Escalation
While listed as Impo
Talos
Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939 , an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here .
Talos also r
Trendmicro
April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
blogs_trendmicro·2020-04-14·CVSS 8.8
[HIGH] April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
## April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
Microsoft’s Patch Tuesday for April released fixes for a couple of critical font-related vulnerabilities, like an earlier disclosed one found in Adobe Type Manager Library (atmfd.dll). It also featured patches for vulnerabilities in Microsoft SharePoint and Windows Components.
By: Trend Micro Apr 14, 2020 Read time: ( words)
Save to Folio
Microsoft fixed 113 vulnerabilities in this month’s Patch Tuesday , just two shy of last month’s 115. This continues the streak of longer-than-usual list of patches that began in January . In fact, compared to the same period in 2019, Microsoft fixed 44% more vulnerabilities between January to April of this year.
In this month’s list, 17 were rate
Trendmicro
April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
blogs_trendmicro·2020-04-14·CVSS 8.8
[HIGH] April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
## April Patch Tuesday: Fixes for Font-Related, Microsoft SharePoint, Windows Components Vulnerabilities
Microsoft’s Patch Tuesday for April released fixes for a couple of critical font-related vulnerabilities, like an earlier disclosed one found in Adobe Type Manager Library (atmfd.dll). It also featured patches for vulnerabilities in Microsoft SharePoint and Windows Components.
By: Trend Micro 2020/04/14 Read time: ( words)
Save to Folio
Microsoft fixed 113 vulnerabilities in this month’s Patch Tuesday , just two shy of last month’s 115. This continues the streak of longer-than-usual list of patches that began in January . In fact, compared to the same period in 2019, Microsoft fixed 44% more vulnerabilities between January to April of this year.
In this month’s list, 17 were rated
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
2020-04-15
Published