EXPOSURES › CVE-2020-1147
CVE-2020-1147
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft .NET Framework, SharePoint, and Visual Studio suffered a remote code execution vulnerability due to unvalidated XML deserialization.
The vulnerability allowed attackers to execute arbitrary code by exploiting unvalidated XML input during deserialization. DIB organizations must ensure all .NET Framework, SharePoint, and Visual Studio components are patched to prevent remote code execution and maintain compliance with CMMC/NIST 800-171 requirements for system integrity and access control.
Shame score — A critical RCE vulnerability in widely deployed Microsoft products was actively exploited in the wild, indicating a failure to patch known, high-severity flaws promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
"Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |