CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 94% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Affected products
- Microsoft .net Core: version 2.1 only; version 3.1 only
- Microsoft .NET Framework: version 2.0 only; version 3.0 only; version 3.5 only; version 4.6.2 only; version 4.7 only; version 4.7.1 only; …
- Microsoft SharePoint Enterprise Server: version 2013 only; version 2016 only
- Microsoft SharePoint Server: version 2010 only; version 2019 only
- Microsoft Visual Studio 2017: from 15.0, up to and including 15.9
- Microsoft Visual Studio 2019: from 16.0, up to and including 16.6
Published 2020-07-14. Last modified 2026-06-17.