{
  "id": "CVE-2020-1147",
  "url": "https://spydr.io/cve/CVE-2020-1147",
  "published": "2020-07-14T23:15:12.057Z",
  "modified": "2026-06-17T03:00:34.930Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.93966,
  "epss_percentile": 0.99845,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-1147"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Microsoft"
  ],
  "products": [
    "Microsoft SharePoint Enterprise Server",
    "Microsoft SharePoint Server",
    "Microsoft Visual Studio 2019",
    "Microsoft Visual Studio 2019 version 16.6 (includes 16.0 - 16.5)",
    "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
    "Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)",
    "Microsoft .NET Core",
    "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2",
    "Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems",
    "Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems",
    "Microsoft .NET Framework 4.8 on Windows Server, version 1803 (Server Core Installation)",
    "Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems",
    "Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems",
    "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems",
    "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems",
    "Microsoft .NET Framework 4.8 on Windows Server 2016",
    "Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)",
    "Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1",
    "Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1",
    "Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems"
  ],
  "cwes": [],
  "description": "A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.exploitalert.com/view-details.html?id=35992",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1147",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2020-1147",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
