PoC Index

CVE-2020-16952

HIGH 8.6EPSS 71.1%

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.</p><p>Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.</p><p>The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.</p>

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
71.09% chance of exploitation in the next 30 days, 99th percentile
Nuclei
high · CWE-346
Published
2020-10-16
Updated
2024-08-04

Proof-of-concept exploits (1)

Nuclei templates (1)

Metasploit modules (1)

References

Related