cbcvebase.
CVE-2020-1024
published 2020-05-21

CVE-2020-1024: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka…

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
10.41%
95.3th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102.

Affected

9 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-1024 is exploited by uploading a specially crafted SharePoint application package to an affected SharePoint server; detection should focus on unusual application package uploads to SharePoint.
  • Successful exploitation results in arbitrary code running in the context of the SharePoint application pool and SharePoint server farm account; monitor for anomalous process execution under these service accounts.
  • CVE-2020-1024 is one of three SharePoint RCEs (alongside CVE-2020-1023 and CVE-2020-1102) that involve uploading a malicious application package; correlate with the other package-upload CVEs when triaging SharePoint alerts.
  • ·The vulnerability stems from SharePoint failing to check the source markup of an application package; the fix corrects this markup validation logic.
  • ·As of the advisory, the vulnerability had not been publicly disclosed or actively exploited in the wild.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.