CVE-2020-1439
published 2020-07-14CVE-2020-1439: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file…
PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
20.27%
97.2th percentile
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_foundation | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered by uploading a specially crafted XML document to a SharePoint server running PerformancePoint Services; monitor for unusual XML file uploads to PerformancePoint endpoints. ↗
- →The vulnerable deserialization occurs in .NET DataSet and DataTable types within PerformancePoint Services; focus detection on unsafe XML deserialization of these types in the SharePoint process responsible for deserializing XML content. ↗
- →Exploitation results in arbitrary code execution in the context of the process responsible for deserialization of XML content; monitor SharePoint worker processes for anomalous child process spawning or unexpected outbound network connections following XML content processing. ↗
- →The root cause is failure to validate the source markup of XML file input in PerformancePoint Services; inspect XML payloads submitted to PerformancePoint for malformed or unexpected markup, particularly those referencing DataSet/DataTable serialization schemas. ↗
- ·Full protection requires patching both the .NET Framework and all additional affected SharePoint/Office products; patching only one component is insufficient. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7vrg-q6mv-3q9x: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of
ghsa_unreviewed·2022-05-24
CVE-2020-1439 [MEDIUM] GHSA-7vrg-q6mv-3q9x: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
Microsoft
PerformancePoint Services Remote Code Execution Vulnerability
vendor_msrc·2020-07-14·CVSS 8.8
CVE-2020-1439 [HIGH] PerformancePoint Services Remote Code Execution Vulnerability
PerformancePoint Services Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content.
To exploit this vulnerability, an attacker could upload a specially crafted document to a server utilizing an affected product to process content.
The security update addresses the vulnerability by correcting how PerformancePoint Services validates the source markup of XML content.
FAQ: Where does this vulnerability present itself?
The vulnerability is found in the DataSet and DataTable typ
No detection rules found.
No public exploits indexed.
Trendmicro
Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
blogs_trendmicro·2020-07-14·CVSS 7.8
[HIGH] Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
# Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs were disclosed through Trend Micro’s Zero Day Initiative (ZDI) program.
By: Trend Micro
2020/07/14
Read time: ( words)
Save to Folio
There has been a common vulnerabilities and exposures (CVE) fixing trend in 2020 Patch Tuesdays. For instance, Microsoft has patched roughly more than 100 vulnerabilities per month in recent bulletins. Similarly, the July update issues 123 patches, including fixes in RemoteFX vGPU, Microsoft Office, Microsoft Windows, OneDrive, and Jet Database Engine.
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs wer
Qualys
July 2020 Patch Tuesday – 123 Vulnerabilities, 18 Critical, Hyper-V RemoteFX, DNS Server, Workstation, Adobe | Qualys
blogs_qualys·2020-07-14·CVSS 9.0
[CRITICAL] July 2020 Patch Tuesday – 123 Vulnerabilities, 18 Critical, Hyper-V RemoteFX, DNS Server, Workstation, Adobe | Qualys
#### Table of Contents
- Workstation Patches
- Windows DNS Server RCE
- Hyper-V RemoteFX vGPU RCE
- Deserialization RCEs in PerformancePoint Services, SharePoint, .NET, and Visual Studio
- Adobe
- About Patch Tuesday
This month’s Microsoft Patch Tuesday addresses 123 vulnerabilities with 18 of them labeled as Critical. The 18 Critical vulnerabilities cover Hyper-V, DNS Server, PerformancePoint, SharePoint Server, Office, Outlook, Remote Desktop, and several other workstation vulnerabilities. Adobe issued patches today for Download Manager, Media Encoder, Genuine Service, ColdFusion, and Creative Cloud.
## Workstation Patches
Today’s patch Tuesday fixes many vulnerabilities that would impact workstations. The Office, Outlook, Remote Desktop Client, DirectWrite, Address Book, LNK, GDI+,
2020-07-14
Published