CVE-2020-1147
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Affected (20)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp2 |
Configuration F
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1809 |
Microsoft Windows Server 2016 | Version 1903 |
Microsoft Windows Server 2019 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.5.2 |
Configuration L
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | Version r2 sp1 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1607 |
Microsoft Windows 7 | All versions |
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Server 2012 | All versions |
Microsoft Windows Server 2016 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2013 sp1 | |
| Version 2010 sp2 | |
| From 15.0 to 15.9 | |
| From 16.0 to 16.6 |
References (11)
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.