← Vulnerability feed

Vulnerability record · CVE-2020-0646 · published 14 January 2020

CVE-2020-0646: Microsoft .NET Framework input validation flaw enables remote code execution

Microsoft · .Net Framework

CVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XML injection (CWE-91). Because the framework fails to validate input correctly, an unauthenticated remote attacker can inject and execute code, making this a high-value target for both initial access and post-exploitation. It is listed in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 99% · top 0.1% CWE-91 · XML injection
9.8CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, confirmed KEV listing, near-maximum EPSS score, and public exploit code make this an urgent, actively exploited remote code execution flaw.

What it is

CVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XML injection (CWE-91). Because the framework fails to validate input correctly, an unauthenticated remote attacker can inject and execute code, making this a high-value target for both initial access and post-exploitation. It is listed in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.

Impact

An attacker can execute arbitrary code in the context of the affected .NET Framework process, potentially leading to full system compromise. Given the framework's broad use, successful exploitation can yield control over the host and any application relying on it.

Attack surface

The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network with no authentication and no user interaction required. The XML injection nature suggests crafted input is processed by a .NET Framework component, though the record does not specify the exact entry point.

Exploitation

CISA added this CVE to the KEV catalog on 2021-11-03, confirming active exploitation in the wild, and EPSS shows a 30-day probability of 0.99222 (99.9th percentile). Public exploit references exist, including a Packet Storm advisory on SharePoint Workflows XOML injection, indicating exploit code is available.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) as the primary remediation.
  • Prioritize patching internet-facing and SharePoint-related .NET Framework deployments, which are the likely attack vector.
  • Restrict or monitor untrusted XML/XOML input reaching .NET Framework components, especially in workflow and web application contexts.
  • Verify patching across all .NET Framework versions in use, since the advisory covers the framework broadly and the record does not list specific affected versions.
  • Review CISA KEV guidance and ensure remediation is completed within required timelines for known-exploited vulnerabilities.

Detection

  • Monitor for anomalous process creation or child processes spawned by .NET Framework application pools (w3wp.exe, wsmprovhost.exe) that may indicate code execution.
  • Inspect web and application logs for crafted XML/XOML payloads targeting SharePoint workflow or .NET input handling endpoints.
  • Alert on unexpected outbound network connections or file writes originating from .NET Framework processes.
  • Correlate endpoint telemetry with known exploit indicators from the Packet Storm advisory and Microsoft guidance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-0646 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft .NET Framework Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-0646 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed7.8CVE-2017-8759Microsoft .NET Framework remote code execution via malicious documentMicrosoft .NET Framework versions 2.0 through 4.7 contain a code injection flaw that lets an attacker run arbitrary code when a crafted document or a…KEVEPSS 89%analysed7.8CVE-2015-1671Microsoft DirectWrite TrueType Font Parsing Remote Code ExecutionThe Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution…KEVEPSS 49%analysed7.5CVE-2024-29059Microsoft .NET Framework error message information disclosureCVE-2024-29059 is an information disclosure flaw in Microsoft .NET Framework, classified as CWE-209 (error message information leak). A remote, unaut…KEVEPSS 99%analysed10.0CVE-2014-4073Microsoft .net framework permissions and access controls vulnerabilityMicrosoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, whi…EPSS 23%10.0CVE-2014-4121Microsoft .net framework vulnerabilityMicrosoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows r…EPSS 19%10.0CVE-2014-1806Microsoft .net framework code injection vulnerabilityThe .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access…EPSS 40%10.0CVE-2013-0073Microsoft .net framework permissions and access controls vulnerabilityThe Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a…EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2020-0646), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.