cbcvebase.
CVE-2020-1181
published 2020-06-09

CVE-2020-1181: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka…

PriorityP270high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
69.30%
99.3th percentile
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_foundation
microsoftmicrosoft_sharepoint_foundation
microsoftmicrosoft_sharepoint_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_foundation
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2010_service_pack_2
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is exploited by an authenticated user creating and invoking a specially crafted page on an affected Microsoft SharePoint Server, abusing unsafe ASP.Net web controls to execute code in the SharePoint application pool process context.
  • The attack vector is a crafted SharePoint page (not the Preview Pane), so detection should focus on unusual page creation and invocation events by authenticated users on SharePoint servers.
  • The Preview Pane is confirmed NOT an attack vector; focus monitoring on direct page creation/invocation rather than preview-based activity.
  • ·Exploitation requires authentication; unauthenticated access attempts would not trigger this vulnerability. Prioritize monitoring authenticated SharePoint user activity.
  • ·Microsoft assessed exploitation as less likely for both latest and older software releases; however, all SharePoint servers should still be prioritized for patching.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8CRITICAL
vendor_oracle8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.