cbcvebase.
CVE-2020-1439
published 2020-07-14

CVE-2020-1439: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file…

PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
20.27%
97.2th percentile
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_enterprise_server
microsoftmicrosoft_sharepoint_foundation
microsoftmicrosoft_sharepoint_server
microsoftmicrosoft_sharepoint_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2013_service_pack_1
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2010_service_pack_2
msrcmicrosoft_sharepoint_server_2019

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by uploading a specially crafted XML document to a SharePoint server running PerformancePoint Services; monitor for unusual XML file uploads to PerformancePoint endpoints.
  • The vulnerable deserialization occurs in .NET DataSet and DataTable types within PerformancePoint Services; focus detection on unsafe XML deserialization of these types in the SharePoint process responsible for deserializing XML content.
  • Exploitation results in arbitrary code execution in the context of the process responsible for deserialization of XML content; monitor SharePoint worker processes for anomalous child process spawning or unexpected outbound network connections following XML content processing.
  • The root cause is failure to validate the source markup of XML file input in PerformancePoint Services; inspect XML payloads submitted to PerformancePoint for malformed or unexpected markup, particularly those referencing DataSet/DataTable serialization schemas.
  • ·Full protection requires patching both the .NET Framework and all additional affected SharePoint/Office products; patching only one component is insufficient.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.