CVE-2020-1147
published 2020-07-14CVE-2020-1147: A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of…
PriorityP186high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
94.24%
99.8th percentile
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Affected
138 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.6 | 3.1.6 |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_10_version_1607 | — | — |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_server_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
other/wEypAcAAQAAAP////8BAAAAAAAAAAwCAAAAXk1pY3Jvc29mdC5Qb3dlclNoZWxsLkVkaXRvciwgVmVyc2lvbj0zLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTMxYmYzODU2YWQzNjRlMzUFAQAAAEJNaWNyb3NvZnQuVmlzdWFsU3R1ZGlvLlRleHQuRm9ybWF0dGluZy5UZXh0Rm9ybWF0dGluZ1J1blByb3BlcnRpZXMBAAAAD0ZvcmVncm91bmRCcnVzaAECAAAABgMAAADGBTw/eG1sIHZlcnNpb249IjEuMCIgZW5jb2Rpbmc9InV0Zi04Ij8+DQo8T2JqZWN0RGF0YVByb3ZpZGVyIE1ldGhvZE5hbWU9IlN0YXJ0IiBJc0luaXRpYWxMb2FkRW5hYmxlZD0iRmFsc2UiIHhtbG5zPSJodHRwOi8vc2NoZW1hcy5taWNyb3NvZnQuY29tL3dpbmZ4LzIwMDYveGFtbC9wcmVzZW50YXRpb24iIHhtbG5zOnNkPSJjbHItbmFtZXNwYWNlOlN5c3RlbS5EaWFnbm9zdGljczthc3NlbWJseT1TeXN0ZW0iIHhtbG5zOng9Imh0dHA6Ly9zY2hlbWFzLm1pY3Jvc29mdC5jb20vd2luZngvMjAwNi94YW1sIj4NCiAgPE9iamVjdERhdGFQcm92aWRlci5PYmplY3RJbnN0YW5jZT4NCiAgICA8c2Q6UHJvY2Vzcz4NCiAgICAgIDxzZDpQcm9jZXNzLlN0YXJ0SW5mbz4NCiAgICAgICAgPHNkOlByb2Nlc3NTdGFydEluZm8gQXJndW1lbnRzPSIvYyBwaW5nIC9uIDEwIDEwLjQ5LjExNy4yNTMiIFN0YW5kYXJkRXJyb3JFbmNvZGluZz0ie3g6TnVsbH0iIFN0YW5kYXJkT3V0cHV0RW5jb2Rpbmc9Int4Ok51bGx9IiBVc2VyTmFtZT0iIiBQYXNzd29yZD0ie3g6TnVsbH0iIERvbWFpbj0iIiBMb2FkVXNlclByb2ZpbGU9IkZhbHNlIiBGaWxlTmFtZT0iY21kIiAvPg0KICAgICAgPC9zZDpQcm9jZXNzLlN0YXJ0SW5mbz4NCiAgICA8L3NkOlByb2Nlc3M+DQogIDwvT2JqZWN0RGF0YVByb3ZpZGVyLk9iamVjdEluc3RhbmNlPg0KPC9PYmplY3REYXRhUHJvdmlkZXI+Cw==↗
- →Monitor POST requests to /_layouts/15/quicklinks.aspx or /_layouts/15/quicklinksdialogform.aspx with a ?Mode=Suggestion query parameter and a populated __SUGGESTIONSCACHE__ form field, which is the exploit delivery mechanism for CVE-2020-1147. ↗
- →The exploit targets the ContactLinksSuggestionsMicroView type (or derivatives) via the __SUGGESTIONSCACHE__ parameter; alert on POST requests to SharePoint quicklinks endpoints containing serialized LosFormatter payloads (base64-encoded, starting with /wEy) in that field. ↗
- →Detect use of ysoserial.exe gadget chains TypeConfuseDelegate or TextFormattingRunProperties with LosFormatter output format, as these are the documented gadget generators for this exploit. ↗
- →Google dork 'inurl:quicklinks.aspx' is used by attackers to identify vulnerable SharePoint targets; monitor for external reconnaissance against this path. ↗
- ·The exploit requires authenticated access (Domain User is sufficient in default SharePoint configurations); a Domain User account is enough to trigger the vulnerability without elevated privileges. ↗
- ·The exploit uses NTLM authentication; environments using non-NTLM auth may behave differently, but the deserialization sink itself is the core risk regardless of auth method. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8CRITICAL
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
ghsa·2022-05-24
CVE-2020-1147 [HIGH] .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
OSV
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
osv·2022-05-24
CVE-2020-1147 [HIGH] .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
VulnCheck
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-1147 [HIGH] Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
Affected: Microsoft .NET Framework, SharePoint, Visual Studio
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
CISA
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-1147 [HIGH] Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Vulnerability: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Affected: Microsoft .NET Framework, SharePoint, Visual Studio
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-1147
Remediation Due Date: 2022-05-03
Red Hat
dotnet: XML source markup processing remote code execution
vendor_redhat·2020-07-14·CVSS 7.8
CVE-2020-1147 [HIGH] CWE-502 dotnet: XML source markup processing remote code execution
dotnet: XML source markup processing remote code execution
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
It was discovered that .NET Core did not properly check the source markup of XML files. A remote, unauthenticated attacker could possibly exploit this flaw to execute arbitrary code by sending specially crafted requests to an application parsing certain kinds of XML files or an ASP.NET Core application.
Microsoft
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2020-07-14·CVSS 7.8
CVE-2020-1147 [HIGH] .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content.
To exploit this vulnerability, an attacker could upload a specially crafted document to a server utilizing an affected product to process content.
The security update addresses the vulnerability by correcting how .NET Framework, Microsoft SharePoint, and Visual Studio validates the source markup of XML content.
FAQ: I am running Windows Server 2008, Window
Suricata
ET EXPLOIT .NET Framework Remote Code Execution Injection (CVE-2020-1147)
suricata·2021-11-18·CVSS 7.8
CVE-2020-1147 [HIGH] ET EXPLOIT .NET Framework Remote Code Execution Injection (CVE-2020-1147)
ET EXPLOIT .NET Framework Remote Code Execution Injection (CVE-2020-1147)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT .NET Framework Remote Code Execution Injection (CVE-2020-1147)"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"__SUGGESTIONSCACHE__"; fast_pattern; content:"<DataSet"; nocase; distance:0; content:"System.Data.Services.Internal.ExpandedWrapper"; nocase; distance:0; reference:url,srcincite.io/blog/2020/07/20/sharepoint-and-pwn-remote-code-execution-against-sharepoint-server-abusing-dataset.html; reference:cve,2020-1147; classtype:attempted-admin; sid:2034510; rev:2; metadata:created_at 2021_11_18, cve CVE_2020_1147, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_
Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
exploitdb·2021-07-23·CVSS 7.8
CVE-2020-1147 [HIGH] Microsoft SharePoint Server 2019 - Remote Code Execution (2)
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
---
# Exploit Title: Microsoft SharePoint Server 2019 - Remote Code Execution (2)
# Google Dork: inurl:quicklinks.aspx
# Date: 2020-08-14
# Exploit Author: West Shepherd
# Vendor Homepage: https://www.microsoft.com
# Version: SharePoint Enterprise Server 2013 Service Pack 1, SharePoint Enterprise Server 2016 , SharePoint Server 2010 Service
# Pack 2, SharePoint Server 2019
# Tested on: Windows 2016
# CVE : CVE-2020-1147
# Credit goes to Steven Seele and Soroush Dalili
# Source: https://srcincite.io/blog/2020/07/20/sharepoint-and-pwn-remote-code-execution-against-sharepoint-server-abusing-dataset.html
#!/usr/bin/python
from sys import argv, exit, stdout, stderr
import argparse
import requests
from bs4 import BeautifulSoup
from
Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution
exploitdb·2020-08-17·CVSS 7.8
CVE-2020-1147 [HIGH] Microsoft SharePoint Server 2019 - Remote Code Execution
Microsoft SharePoint Server 2019 - Remote Code Execution
---
# Exploit Title: Microsoft SharePoint Server 2019 - Remote Code Execution
# Google Dork: inurl:quicklinks.aspx
# Date: 2020-08-14
# Exploit Author: West Shepherd
# Vendor Homepage: https://www.microsoft.com
# Version: SharePoint Enterprise Server 2013 Service Pack 1, SharePoint Enterprise Server 2016 , SharePoint Server 2010 Service
# Pack 2, SharePoint Server 2019
# Tested on: Windows 2016
# CVE : CVE-2020-1147
# Credit goes to Steven Seele and Soroush Dalili
# Source: https://srcincite.io/blog/2020/07/20/sharepoint-and-pwn-remote-code-execution-against-sharepoint-server-abusing-dataset.html
#!/usr/bin/python
from sys import argv, exit, stdout, stderr
import argparse
import requests
from bs4 import BeautifulSoup
from requests
Metasploit
SharePoint DataSet / DataTable Deserialization
metasploit
SharePoint DataSet / DataTable Deserialization
SharePoint DataSet / DataTable Deserialization
A remotely exploitable vulnerability exists within SharePoint that can be leveraged by a remote authenticated attacker to execute code within the context of the SharePoint application service. The privileges in this execution context are determined by the account that is specified when SharePoint is installed and configured. The vulnerability is related to a failure to validate the source of XML input data, leading to an unsafe deserialization operation that can be triggered from a page that initializes either the ContactLinksSuggestionsMicroView type or a derivative of it. In a default configuration, a Domain User account is sufficient to access SharePoint and exploit this vulnerability.
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Securelist
ToolShell: a story of five vulnerabilities in Microsoft SharePoint
blogs_securelist·2025-07-25·CVSS 7.8
CVE-2025-49706 [HIGH] ToolShell: a story of five vulnerabilities in Microsoft SharePoint
Table of Contents
- The exploit
- CVE-2025-49706
- CVE-2025-53771
- CVE-2025-49704
- CVE-2025-53770
- CVE-2020-1147
- Conclusions
Authors
- Boris Larin
- Georgy Kucherin
- Ilya Savelyev
On July 19–20, 2025, various security companies and national CERTs published alerts about active exploitation of on-premise SharePoint servers. According to the reports, observed attacks did not require authentication, allowed attackers to gain full control over the infected servers, and were performed using an exploit chain of two vulnerabilities: CVE-2025-49704 and CVE-2025-49706, publicly named “ToolShell”. Additionally, on the same dates, Microsoft released out-of-band security patches for the vulnerabilities CVE-2025-53770 and CVE-2025-53771, aimed at addressing the security bypasses of previously
Securelist
ToolShell: a story of five vulnerabilities in Microsoft SharePoint
blogs_securelist·2025-07-25·CVSS 7.8
CVE-2025-49706 [HIGH] ToolShell: a story of five vulnerabilities in Microsoft SharePoint
Table of Contents
The exploit
CVE-2025-49706
CVE-2025-53771
CVE-2025-49704
CVE-2025-53770
CVE-2020-1147
Conclusions
Authors
Boris Larin
Georgy Kucherin
Ilya Savelyev
On July 19–20, 2025, various security companies and national CERTs published alerts about active exploitation of on-premise SharePoint servers. According to the reports, observed attacks did not require authentication, allowed attackers to gain full control over the infected servers, and were performed using an exploit chain of two vulnerabilities: CVE-2025-49704 and CVE-2025-49706 , publicly named “ToolShell”. Additionally, on the same dates, Microsoft released out-of-band security patches for the vulnerabilities CVE-2025-53770 and CVE-2025-53771 , aimed at addressing the security bypasses of previously issued fix
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Trendmicro
Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
blogs_trendmicro·2020-07-14·CVSS 7.8
[HIGH] Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
# Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs were disclosed through Trend Micro’s Zero Day Initiative (ZDI) program.
By: Trend Micro
2020/07/14
Read time: ( words)
Save to Folio
There has been a common vulnerabilities and exposures (CVE) fixing trend in 2020 Patch Tuesdays. For instance, Microsoft has patched roughly more than 100 vulnerabilities per month in recent bulletins. Similarly, the July update issues 123 patches, including fixes in RemoteFX vGPU, Microsoft Office, Microsoft Windows, OneDrive, and Jet Database Engine.
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs wer
Qualys
July 2020 Patch Tuesday – 123 Vulnerabilities, 18 Critical, Hyper-V RemoteFX, DNS Server, Workstation, Adobe | Qualys
blogs_qualys·2020-07-14·CVSS 9.0
[CRITICAL] July 2020 Patch Tuesday – 123 Vulnerabilities, 18 Critical, Hyper-V RemoteFX, DNS Server, Workstation, Adobe | Qualys
#### Table of Contents
- Workstation Patches
- Windows DNS Server RCE
- Hyper-V RemoteFX vGPU RCE
- Deserialization RCEs in PerformancePoint Services, SharePoint, .NET, and Visual Studio
- Adobe
- About Patch Tuesday
This month’s Microsoft Patch Tuesday addresses 123 vulnerabilities with 18 of them labeled as Critical. The 18 Critical vulnerabilities cover Hyper-V, DNS Server, PerformancePoint, SharePoint Server, Office, Outlook, Remote Desktop, and several other workstation vulnerabilities. Adobe issued patches today for Download Manager, Media Encoder, Genuine Service, ColdFusion, and Creative Cloud.
## Workstation Patches
Today’s patch Tuesday fixes many vulnerabilities that would impact workstations. The Office, Outlook, Remote Desktop Client, DirectWrite, Address Book, LNK, GDI+,
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Crowdstrike
Vulnerability Roundup: 10 Critical CVEs of 2020
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Vulnerability Roundup: 10 Critical CVEs of 2020
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Bugzilla
CVE-2020-1147 dotnet: XML source markup processing remote code execution
bugzilla·2020-07-14·CVSS 7.8
CVE-2020-1147 [HIGH] CVE-2020-1147 dotnet: XML source markup processing remote code execution
CVE-2020-1147 dotnet: XML source markup processing remote code execution
It was discovered that .NET Core did not properly check the source markup of XML files. A remote, unauthenticated attacker could exploit this flaw to execute arbitrary code by sending specially crafted requests to an application parsing certain kinds of XML files or an ASP.NET Core application.
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147
https://github.com/dotnet/announcements/issues/159
Discussion:
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:2937 https://access.redhat.com/errata/RHSA-2020:2937
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Li
http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.htmlhttp://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147https://www.exploitalert.com/view-details.html?id=35992http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.htmlhttp://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147https://www.exploitalert.com/view-details.html?id=35992https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1147
2020-07-14
Published
2021-11-03
Added to CISA KEV
Exploited in the wild