CVE-2020-1147

EUVD-2022-3898
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
microsoft.net_core
2.1
microsoft.net_core
3.1
microsoft.net_framework
2.0:sp2
microsoft.net_framework
3.0:sp2
microsoft.net_framework
3.5
microsoft.net_framework
3.5
microsoft.net_framework
4.6.2
microsoft.net_framework
4.7
microsoft.net_framework
4.7.1
microsoft.net_framework
4.7.2
microsoft.net_framework
3.5
microsoft.net_framework
4.6
microsoft.net_framework
4.6.1
microsoft.net_framework
4.6.2
microsoft.net_framework
3.5
microsoft.net_framework
4.6
microsoft.net_framework
4.6.1
microsoft.net_framework
4.6.2
microsoft.net_framework
3.5
microsoft.net_framework
4.7.1
microsoft.net_framework
4.7.2
microsoft.net_framework
3.5
microsoft.net_framework
4.7.2
microsoft.net_framework
3.5
microsoft.net_framework
4.8
microsoft.net_framework
3.5.1
microsoft.net_framework
4.5.2
microsoft.net_framework
4.6
microsoft.net_framework
4.6
microsoft.net_framework
4.6.1
microsoft.net_framework
4.6.2
microsoft.net_framework
4.7
microsoft.net_framework
4.7.1
microsoft.net_framework
4.7.2
microsoft.net_framework
4.8
microsoftvisual_studio_2017
15.0 ≤
𝑥
≤ 15.9
microsoftvisual_studio_2019
16.0 ≤
𝑥
≤ 16.6
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 10
(x64, x86)
1607 (x64, x86)
1607 (x64, x86)
1709 (arm64, x64, x86)
1709 (x64, x86)
1803 (arm64, x64, x86)
1803 (x64, x86)
1809 (arm64, x64, x64, x86, x86)
1903 (arm64, x64, x86)
1909 (arm64, x64, x86)
2004 (arm64, x64, x86)
Windows 7
Service Pack 1 (x64, x86)
Service Pack 1 (x64, x64, x64, x86, x86, x86)
Windows 8.1
(x64, x64, x64, x64, x86, x86, x86, x86)
(x64, x64, x86, x86)
Windows RT 8.1
All
Windows Server
1803 Server Core
1803 Server Core
1903 Server Core
1909 Server Core
2004 Server Core
Windows Server 2008
Service Pack 2 (x64, x86)
Service Pack 2 (x64, x64, x86, x86)
Windows Server 2008 R2
Service Pack 1 (x64)
Service Pack 1 (x64, x64, x64)
Service Pack 1 Server Core (x64)
Service Pack 1 Server Core (x64, x64)
Windows Server 2012
Server Core
Standard
Windows Server 2012 R2
Server Core
Server Core
Standard
Standard
Windows Server 2016
Server Core
Server Core
Standard
Standard
Windows Server 2019
Server Core
Standard