vulnti.work

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2020-1147
First seen2021-11-03 00:00 UTC
Disclosed2021-11-03 00:00 UTC
Last updated2026-07-18 08:00 UTC
Channel statuspending_review

Summary

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Microsoft:.NET Framework, SharePoint, Visual Studio

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV