CVE-2020-1210
published 2020-09-11CVE-2020-1210: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker…
PriorityP183high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
1.76%
75.5th percentile
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_business_productivity_servers_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_business_productivity_servers_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is uploading a specially crafted SharePoint application package to a vulnerable SharePoint site; monitor for suspicious .app/.wsp package uploads to SharePoint ↗
- →Successful exploitation results in code execution under the SharePoint application pool identity and SharePoint server farm account; monitor for anomalous process spawning from SharePoint worker processes (w3wp.exe) ↗
- →Ransomware actors have historically targeted SharePoint vulnerabilities; prioritize detection of lateral movement and ransomware staging activity following any SharePoint compromise ↗
- →The Preview Pane is NOT an attack vector; focus detection on upload/import endpoints rather than document preview activity ↗
- ·Vulnerability root cause is failure to check source markup of an application package; detection logic should focus on malformed or unexpected markup within uploaded SharePoint app packages ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck9.9CRITICAL
vendor_msrc9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mj64-4vr6-2hqr: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.6
CVE-2020-1210 [HIGH] CWE-494 GHSA-mj64-4vr6-2hqr: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1452, CVE-2020-1453, CVE-2020-1576, CVE-2020-1595.
GHSA
GHSA-qrj7-px96-x7pw: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.6
CVE-2020-1576 [HIGH] CWE-494 GHSA-qrj7-px96-x7pw: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1453, CVE-2020-1595.
GHSA
GHSA-45fv-9g2p-xqxq: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.6
CVE-2020-1453 [HIGH] CWE-494 GHSA-45fv-9g2p-xqxq: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1576, CVE-2020-1595.
GHSA
GHSA-85x5-vr9q-4m59: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft Share
ghsa_unreviewed·2022-05-24·CVSS 8.6
CVE-2020-1595 [HIGH] CWE-494 GHSA-85x5-vr9q-4m59: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft Share
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1453, CVE-2020-1576.
GHSA
GHSA-fw5p-r5cw-5r92: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 8.6
CVE-2020-1452 [HIGH] CWE-494 GHSA-fw5p-r5cw-5r92: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1453, CVE-2020-1576, CVE-2020-1595.
GHSA
GHSA-56px-8q45-w6v6: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
ghsa_unreviewed·2022-05-24·CVSS 9.9
CVE-2020-1200 [CRITICAL] CWE-494 GHSA-56px-8q45-w6v6: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1210, CVE-2020-1452, CVE-2020-1453, CVE-2020-1576, CVE-2020-1595.
VulnCheck
Microsoft SharePoint Download of Code Without Integrity Check
vulncheck·2020·CVSS 9.9
CVE-2020-1210 [CRITICAL] Microsoft SharePoint Download of Code Without Integrity Check
Microsoft SharePoint Download of Code Without Integrity Check
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
Affected: Microsoft SharePoint
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the prod
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2020-09-08·CVSS 9.9
CVE-2020-1210 [CRITICAL] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, Sept. 2020 Edition
blogs_krebs·2020-09-23·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday, Sept. 2020 Edition
Microsoft today released updates to remedy nearly 130 security vulnerabilities in its Windows operating system and supported software. None of the flaws are known to be currently under active exploitation, but 23 of them could be exploited by malware or malcontents to seize complete control of Windows computers with little or no help from users.
The majority of the most dangerous or “critical” bugs deal with issues in Microsoft’s various Windows operating systems and its web browsers, Internet Explorer and Edge. September marks the seventh month in a row Microsoft has shipped fixes for more than 100 flaws in its products, and the fourth month in a row that it fixed more than 120.
Among the chief concerns for enterprises this month is CVE-2020-16875, which involves a critical flaw in the
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
# September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro
2020/09/09
Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service (D
Krebs
Microsoft Patch Tuesday, Sept. 2020 Edition
blogs_krebs·2020-09-08·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday, Sept. 2020 Edition
Microsoft today released updates to remedy nearly 130 security vulnerabilities in its Windows operating system and supported software. None of the flaws are known to be currently under active exploitation, but 23 of them could be exploited by malware or malcontents to seize complete control of Windows computers with little or no help from users.
The majority of the most dangerous or “critical” bugs deal with issues in Microsoft’s various Windows operating systems and its web browsers, Internet Explorer and Edge . September marks the seventh month in a row Microsoft has shipped fixes for more than 100 flaws in its products, and the fourth month in a row that it fixed more than 120.
Among the chief concerns for enterprises this month is CVE-2020-16875 , which involves a critical flaw in th
Qualys
September 2020 Patch Tuesday – 129 Vulnerabilities, 23 Critical, SharePoint, Exchange, Windows Codecs, Adobe Vulns
blogs_qualys·2020-09-08·CVSS 8.6
[HIGH] September 2020 Patch Tuesday – 129 Vulnerabilities, 23 Critical, SharePoint, Exchange, Windows Codecs, Adobe Vulns
This month’s Microsoft Patch Tuesday addresses 129 vulnerabilities with 23 of them labeled as Critical. The 23 Critical vulnerabilities cover SharePoint, Exchange, Dynamics 365, Windows Codecs, and several other workstation vulnerabilities. Adobe released patches today for Experience Manager, Framemaker, and InDesign.
## Workstation Patches
Continuing the trend, today’s Patch Tuesday fixes many vulnerabilities that would impact workstations. The Windows Codecs, GDI+, Browser, COM, and Text Service Module vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## SharePoint RCEs
Microsoft patched seven vulnerabilities
Tenable
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
blogs_tenable·2020-09-08
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
September 2020 Patch Tuesday – 129 Vulnerabilities, 23 Critical, SharePoint, Exchange, Windows Codecs, Adobe Vulns | Qualys
blogs_qualys·2020-09-08·CVSS 8.6
[HIGH] September 2020 Patch Tuesday – 129 Vulnerabilities, 23 Critical, SharePoint, Exchange, Windows Codecs, Adobe Vulns | Qualys
This month’s Microsoft Patch Tuesday addresses 129 vulnerabilities with 23 of them labeled as Critical. The 23 Critical vulnerabilities cover SharePoint, Exchange, Dynamics 365, Windows Codecs, and several other workstation vulnerabilities. Adobe released patches today for Experience Manager, Framemaker, and InDesign.
### Workstation Patches
Continuing the trend, today’s Patch Tuesday fixes many vulnerabilities that would impact workstations. The Windows Codecs, GDI+, Browser, COM, and Text Service Module vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### SharePoint RCEs
Microsoft patched seven vulnerabiliti
2020-09-11
Published
Exploited in the wild