PoC Index

CVE-2020-1147

KEVHIGH 7.8EPSS 94.0%

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
93.97% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2021-11-03
Nuclei
critical
Published
2020-07-14
Updated
2025-10-21

Proof-of-concept exploits (3)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (2)

References

Related