PT-2020-3077 · Microsoft +3 · Visual Studio +5

Published

2020-07-14

·

Updated

2025-08-25

·

CVE-2020-1147

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions:**

.NET Core versions prior to 3.1.106

.NET Core Runtime versions prior to 2.1.20

.NET Core SDK versions prior to 2.1.516

Microsoft .NET Framework (affected versions not specified)

Microsoft SharePoint Server (affected versions not specified)

Microsoft SharePoint Enterprise Server (affected versions not specified)

Microsoft Visual Studio (affected versions not specified)

MS Lync/Skype for Business (affected versions not specified)

**Description:**

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content. The vulnerability stems from an incomplete fix for a flaw initially reported in 2020 and has been actively exploited in recent ToolShell attacks targeting on-premises Microsoft SharePoint servers. The vulnerability is related to the processing of XML data and can be triggered by uploading a specially crafted document. The issue affects .NET dataset and datatable types.

**Recommendations:**

Update .NET Core to version 3.1.106 or later.

Update .NET Core Runtime to version 2.1.20 or later.

Update .NET Core SDK to version 2.1.516 or later.

At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft .NET Framework, Microsoft SharePoint Server, Microsoft SharePoint Enterprise Server, MS Lync/Skype for Business and Microsoft Visual Studio.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2513
ALT-PU-2020-2514
ALT-PU-2020-2592
ALT-PU-2020-2593
BDU:2020-03369
CESA-2020_2938
CESA-2020_2954
CVE-2020-1147
GHSA-G5VF-38CP-4PX9
RHSA-2020:2937
RHSA-2020:2938
RHSA-2020:2939
RHSA-2020:2954
RHSA-2020:2988
RHSA-2020:2989
RHSA-2020_2938
RHSA-2020_2954

Affected Products

.Net Framework
Alt Linux
Centos
Sharepoint Server
Red Hat
Visual Studio