← Vulnerability feed

Vulnerability record · CVE-2020-1147 · published 14 July 2020

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCE

Microsoft · .Net Core

The software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affects .NET Framework, .NET Core, SharePoint Server/Enterprise Server, and Visual Studio 2017/2019. Because the affected components are widely deployed and public exploit code exists, this is a high-value target for defenders.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 94% · top 0.2%
7.8CVSS 3.1 base score, v2 6.8
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
11References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with public exploit code, a near-maximum EPSS score, and remote code execution impact across widely deployed Microsoft products.

What it is

The software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affects .NET Framework, .NET Core, SharePoint Server/Enterprise Server, and Visual Studio 2017/2019. Because the affected components are widely deployed and public exploit code exists, this is a high-value target for defenders.

Impact

An attacker who gets a crafted XML document processed can execute arbitrary code in the context of the affected application or user. On SharePoint this can mean code execution on the server; on client-side .NET/Visual Studio it means code execution on the workstation.

Attack surface

Reached by delivering a malicious XML file or payload to a vulnerable XML-processing path, such as a SharePoint DataSet/DataTable deserialization endpoint or a .NET application that parses untrusted XML. The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so exploitation depends on the victim opening or processing the crafted content.

Exploitation

CVE-2020-1147 is listed in CISA KEV (added 2021-11-03) and has a very high EPSS probability of about 0.94 (99.8th percentile), and multiple references are tagged Exploit, indicating public exploit code is available. No ransomware campaign use is documented.

What to do

  • Apply the Microsoft security update for .NET Framework, .NET Core, SharePoint Server/Enterprise Server, and Visual Studio 2017/2019 as listed in the vendor advisory.
  • Restrict or disable processing of untrusted XML input in affected .NET applications and SharePoint workflows where feasible.
  • Enforce SharePoint patch levels and review custom web parts or solutions that deserialize XML.
  • Block or inspect inbound XML attachments and uploads at email and web gateways.
  • Monitor for and remove public exploit tooling targeting SharePoint DataSet/DataTable deserialization.

Detection

  • Hunt for w3wp.exe or SharePoint processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
  • Monitor for XML uploads or POST bodies containing DataSet/DataTable or ObjectDataProvider deserialization markers.
  • Alert on suspicious outbound connections from SharePoint or .NET application hosts following XML processing.
  • Review IIS and SharePoint logs for anomalous requests to XML-handling endpoints around the time of process creation events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-1147 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-1147 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-20963Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 30%analysed9.8CVE-2025-53770Microsoft SharePoint Server deserialization RCE under active exploitationOn-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft st…KEVEPSS 100%analysed9.8CVE-2023-29357Microsoft SharePoint Server elevation of privilege via authentication bypassCVE-2023-29357 is a critical elevation of privilege flaw in Microsoft SharePoint Server. The CVSS vector shows it is network reachable with no privil…KEVEPSS 100%analysed9.8CVE-2020-0646Microsoft .NET Framework input validation flaw enables remote code executionCVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XM…KEVEPSS 99%analysed9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-1147), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.