Skip to main content

CVE-2020-1147

7.8
HIGHCVSS v3.1 Base Score
93.43%
HIGH RiskEPSS (100th percentile)
KEV
NVD-CWE-Other

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

Published: 7/14/2020
Modified: 10/29/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Vendor / Product:

Microsoft .NET Framework, SharePoint, Visual Studio

Required Action:

Apply updates per vendor instructions.

Due Date: 5/3/2022(OVERDUE)
Added to KEV:

11/3/2021

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2020-1147

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

93.43%HIGH Exploitation Risk
100th percentile

This vulnerability has a 93.43% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-Other

Related Vulnerabilities