Vulnerability record · CVE-2020-1147 · published 14 July 2020
CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCE
Microsoft · .Net Core
The software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affects .NET Framework, .NET Core, SharePoint Server/Enterprise Server, and Visual Studio 2017/2019. Because the affected components are widely deployed and public exploit code exists, this is a high-value target for defenders.
Description
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with public exploit code, a near-maximum EPSS score, and remote code execution impact across widely deployed Microsoft products.
What it is
The software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affects .NET Framework, .NET Core, SharePoint Server/Enterprise Server, and Visual Studio 2017/2019. Because the affected components are widely deployed and public exploit code exists, this is a high-value target for defenders.
Impact
An attacker who gets a crafted XML document processed can execute arbitrary code in the context of the affected application or user. On SharePoint this can mean code execution on the server; on client-side .NET/Visual Studio it means code execution on the workstation.
Attack surface
Reached by delivering a malicious XML file or payload to a vulnerable XML-processing path, such as a SharePoint DataSet/DataTable deserialization endpoint or a .NET application that parses untrusted XML. The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so exploitation depends on the victim opening or processing the crafted content.
Exploitation
CVE-2020-1147 is listed in CISA KEV (added 2021-11-03) and has a very high EPSS probability of about 0.94 (99.8th percentile), and multiple references are tagged Exploit, indicating public exploit code is available. No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update for .NET Framework, .NET Core, SharePoint Server/Enterprise Server, and Visual Studio 2017/2019 as listed in the vendor advisory.
- Restrict or disable processing of untrusted XML input in affected .NET applications and SharePoint workflows where feasible.
- Enforce SharePoint patch levels and review custom web parts or solutions that deserialize XML.
- Block or inspect inbound XML attachments and uploads at email and web gateways.
- Monitor for and remove public exploit tooling targeting SharePoint DataSet/DataTable deserialization.
Detection
- Hunt for w3wp.exe or SharePoint processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Monitor for XML uploads or POST bodies containing DataSet/DataTable or ObjectDataProvider deserialization markers.
- Alert on suspicious outbound connections from SharePoint or .NET application hosts following XML processing.
- Review IIS and SharePoint logs for anomalous requests to XML-handling endpoints around the time of process creation events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-1147 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-1147 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-1147), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.