Vulnerability record · CVE-2020-0646 · published 14 January 2020
CVE-2020-0646: Microsoft .NET Framework input validation flaw enables remote code execution
Microsoft · .Net Framework
CVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XML injection (CWE-91). Because the framework fails to validate input correctly, an unauthenticated remote attacker can inject and execute code, making this a high-value target for both initial access and post-exploitation. It is listed in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.
Description
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed KEV listing, near-maximum EPSS score, and public exploit code make this an urgent, actively exploited remote code execution flaw.
What it is
CVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XML injection (CWE-91). Because the framework fails to validate input correctly, an unauthenticated remote attacker can inject and execute code, making this a high-value target for both initial access and post-exploitation. It is listed in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.
Impact
An attacker can execute arbitrary code in the context of the affected .NET Framework process, potentially leading to full system compromise. Given the framework's broad use, successful exploitation can yield control over the host and any application relying on it.
Attack surface
The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network with no authentication and no user interaction required. The XML injection nature suggests crafted input is processed by a .NET Framework component, though the record does not specify the exact entry point.
Exploitation
CISA added this CVE to the KEV catalog on 2021-11-03, confirming active exploitation in the wild, and EPSS shows a 30-day probability of 0.99222 (99.9th percentile). Public exploit references exist, including a Packet Storm advisory on SharePoint Workflows XOML injection, indicating exploit code is available.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) as the primary remediation.
- Prioritize patching internet-facing and SharePoint-related .NET Framework deployments, which are the likely attack vector.
- Restrict or monitor untrusted XML/XOML input reaching .NET Framework components, especially in workflow and web application contexts.
- Verify patching across all .NET Framework versions in use, since the advisory covers the framework broadly and the record does not list specific affected versions.
- Review CISA KEV guidance and ensure remediation is completed within required timelines for known-exploited vulnerabilities.
Detection
- Monitor for anomalous process creation or child processes spawned by .NET Framework application pools (w3wp.exe, wsmprovhost.exe) that may indicate code execution.
- Inspect web and application logs for crafted XML/XOML payloads targeting SharePoint workflow or .NET input handling endpoints.
- Alert on unexpected outbound network connections or file writes originating from .NET Framework processes.
- Correlate endpoint telemetry with known exploit indicators from the Packet Storm advisory and Microsoft guidance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-0646 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft .NET Framework Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156930/SharePoint-Workflows-XOML-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/156930/SharePoint-Workflows-XOML-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0646 | US Government Resource |
Track CVE-2020-0646 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-0646), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.