Rapid7

The Command Platform

Respond faster and outpace attackers. Taking command of your attack surface starts here.

Explore platform

Capabilities
  • Exposure Management
    Identify & remediate at-risk data
  • Attack Surface Management
    Reveal & protect coverage gaps
  • Vulnerability Management
    Pinpoint & eliminate risk
  • Cloud-Native Application Protection
    Discover & defend sensitive data
  • Application Security
    Scan & simplify dev workflows

  • Next-Gen SIEM
    Investigate with AI-driven detections
  • Threat Intelligence Platform
    Recognize & mitigate adversaries

Explore the platform
  • Start a Free Trial
    TRY NOW
  • AI-Engine
  • Rapid7 Labs
  • Self-Guided Platform Tour
  • Talk to an Expert
  • Rapid7 Threat Intelligence

All Products


MDR Services
  • Managed Detection and Response
    Preemptive MDR that disrupts attackers
  • MDR for Microsoft
    Maximize and protect your Microsoft investment
  • MDR for Enterprise
    Get customized protection for enterprise systems
  • Incident Response Services
    Get help with an active breach

  • Rapid7 vs. Them
    Decide which solution fits
  • Customer Stories
    Read about real benefits
  • MDR Product Tour
    Experience the functionality
  • MDR ROI Calculator
    See how MDR can boost your ROI

Exposure Management
  • Managed Vulnerability Management
    Get help pinpointing exposures
  • Continuous Red Teaming
    Get help validating exposures
  • Managed Application Security
    Get help securing dev workflows
  • Penetration Testing Services
    Get help with defense assessment

All services


Threat Alert Center
  • Rapid7 Labs
    RESEARCH
    Intelligence, Threat Data & Research
  • Emergent Threat Response
    Latest on the blog
  • Vulnerability & Exploit Database
    Search thousands of CVEs

Learn
  • Blog
  • Webinars and Events
  • Resource Library
  • Cybersecurity Fundamentals

Product
  • Product Documentation
  • Product Release Notes
  • Product Extensions
  • Product Toolkits

Customer Support
  • Customer Support
  • Rapid7 Forum


Partner With Rapid7
  • Partnerships Overview
  • PACT Partner Program
    Expand & enrich customer experience
  • PACT for Service Providers
    Unlock SOC efficiencies

For Customers
  • Partner Directory
    Find Resellers, MSSPs and Distributors
  • Technology Partners
    Strengthen your security stack
  • AWS Partnership
    Secure AWS resource types

Partner portal
  • Partner Login
  • Become a Partner
    Develop & win business


Company
  • About Us
  • Leadership Team
  • Our Customers
  • Careers
  • Contact Us

Media
  • Newsroom
  • Awards and Recognition
  • Investors

In the community
  • Social Good
  • Culture
  • Boston Bruins Partnership

Contact
Log in
Request Demo
BACK TO VEDB

CVE-2020-1147: Undefined Security Weakness

REQUEST DEMO

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CVSS Details

  • CVSS 3.1 Base Score: 7.8
  • CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Covered by Rapid7

ProductVendor AdvisorySolution FileAddedPublished
Centos_linux—
Upgrade dotnet-hostfxr-3.1Upgrade dotnet-templates-3.1Upgrade dotnet-sdk-3.1Upgrade dotnet-host-fxr-2.1Upgrade dotnet-sdk-2.1.5xxUpgrade aspnetcore-targeting-pack-3.1Upgrade dotnet-sdk-2.1Upgrade netstandard-targeting-pack-2.1Upgrade dotnetUpgrade dotnet-hostfxr-3.1-debuginfoUpgrade dotnet-targeting-pack-3.1Upgrade dotnet-apphost-pack-3.1Upgrade dotnet-runtime-2.1Upgrade dotnet3.1-debuginfoUpgrade dotnet-sdk-3.1-debuginfoUpgrade dotnet-runtime-3.1-debuginfoUpgrade dotnet-host-fxr-2.1-debuginfoUpgrade dotnet-runtime-2.1-debuginfoUpgrade dotnet-runtime-3.1Upgrade dotnet-sdk-2.1.5xx-debuginfoUpgrade dotnet-debugsourceUpgrade dotnet-hostUpgrade dotnet-debuginfoUpgrade dotnet3.1-debugsourceUpgrade dotnet-host-debuginfoUpgrade dotnet-apphost-pack-3.1-debuginfoUpgrade aspnetcore-runtime-3.1
Jul 16, 2020Jul 14, 2020
Microsoft Sharepoint—
Download and install Microsoft KB4484453Download and install Microsoft KB4484436
May 15, 2023Jul 14, 2020
Microsoft Visual_studio—
Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.
Jun 25, 2025Jul 14, 2020
Msft—
2020-07 Cumulative Update for .NET Framework 3.5 and 4.7.2 for Windows 10 Version 1809 for ARM64 (KB4565625)Apply update KB4580327 for Microsoft .NET Framework 3.5\4.6\4.6.1\4.6.22020-10 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server, version 2004 for x64 (KB4578968)Security Update for Microsoft SharePoint Enterprise Server 2013 (KB4484443)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows 7 (KB4565583)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 7 for x64 (KB4565586)2020-10 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server, version 1903 for x64 (KB4578974)2020-07 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server, version 2004 for x64 (KB4565627)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows Embedded 8 Standard (KB4565584)2020-07 Security Only Update for .NET Framework 3.5.1 for Windows 7 (KB4565579)2020-07 Security Only Update for .NET Framework 3.5.1 for Windows Embedded Standard 7 for x64 (KB4565579)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows 8.1 and Server 2012 R2 for x64 (KB4565581)2020-07 Security Only Update for .NET Framework 4.8 for Windows Server 2008 R2 for x64 (KB4565589)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows Server 2008 R2 for x64 (KB4565583)2020-10 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server, version 20H2 for x64 (KB4578968)Apply update KB4578973 for Microsoft .NET Framework 3.5\4.82020-07 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4565489)2020-07 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4565511)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows Server 2012 for x64 (KB4565582)2020-07 Security Only Update for .NET Framework 4.6 for Windows Server 2008 SP2 (KB4565586)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 8.1 and Server 2012 R2 for x64 (KB4565585)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows Embedded Standard 7 for x64 (KB4565583)2020-07 Security Only Update for .NET Framework 3.5 for Windows 8.1 and Server 2012 R2 for x64 (KB4565580)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows 8.1 (KB4565581)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows Server 2008 SP2 for x64 (KB4565583)2020-07 Security Only Update for .NET Framework 3.5.1 for Windows Embedded Standard 7 (KB4565579)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows Embedded Standard 7 (KB4565583)2020-07 Security Only Update for .NET Framework 3.5.1 for Windows Server 2008 R2 for x64 (KB4565579)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows Embedded 8 Standard for x64 (KB4565584)2020-07 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4565489)2020-07 Security Only Update for .NET Framework 2.0, 3.0 for Windows Server 2008 SP2 for x64 (KB4565578)2020-07 Security Only Update for .NET Framework 4.8 for Windows 7 for x64 (KB4565589)2020-07 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4565513)2020-07 Cumulative Update for Microsoft Windows Server 2016, version 1607 (KB4565511)2020-07 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4565511)2020-07 Security Only Update for .NET Framework 3.5 for Windows 8.1 (KB4565580)Apply update KB4578969 for Microsoft .NET Framework 4.8Apply update KB4578968 for Microsoft .NET Framework 3.5\4.8Apply update KB4578974 for Microsoft .NET Framework 3.5\4.82020-07 Security Only Update for .NET Framework 4.5.2 for Windows Embedded 8 Standard (KB4565582)Apply update KB4578971 for Microsoft .NET Framework 4.82020-07 Security Only Update for .NET Framework 4.8 for Windows Embedded Standard 7 (KB4565589)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows Embedded Standard 7 for x64 (KB4565586)Apply update KB4580330 for Microsoft .NET Framework 3.5\4.7.22020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows Server 2008 R2 for x64 (KB4565586)2020-07 Security and Quality Rollup for .NET Framework 4.8 for Windows Server 2008 R2 for x64 (KB4565636)2020-07 Security Only Update for .NET Framework 4.8 for Windows Embedded 8 Standard for x64 (KB4565587)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 7 (KB4565586)2020-07 Security Only Update for .NET Framework 2.0, 3.0 for Windows Server 2008 SP2 (KB4565578)2020-07 Security Only Update for .NET Framework 3.5 for Windows Embedded 8 Standard for x64 (KB4565577)Apply update KB4578966 for Microsoft .NET Framework 3.5\4.7.22020-07 Security Only Update for .NET Framework 4.5.2 for Windows Embedded 8 Standard for x64 (KB4565582)2020-07 Security Only Update for .NET Framework 4.8 for Windows 8.1 (KB4565588)2020-07 Security Only Update for .NET Framework 3.5.1 for Windows 7 for x64 (KB4565579)2020-07 Security Only Update for .NET Framework 3.5 for Windows Embedded 8 Standard (KB4565577)Apply update KB4580346 for Microsoft .NET Framework 3.5\4.6.2\4.7\4.7.1\4.7.22020-10 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server, version 1909 for x64 (KB4578974)2020-10 Cumulative Update for Microsoft Windows Server 2016, version 1607 (KB4580346)2020-07 Security Only Update for .NET Framework 4.5.2 for Windows 7 for x64 (KB4565583)2020-07 Security Only Update for .NET Framework 4.6 for Windows Server 2008 SP2 for x64 (KB4565586)2020-07 Security Only Update for .NET Framework 4.8 for Windows Embedded Standard 7 for x64 (KB4565589)2020-07 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4565508)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows Server 2012 for x64 (KB4565584)2020-07 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4565513)Apply update KB4578972 for Microsoft .NET Framework 4.82020-07 Security Only Update for .NET Framework 4.5.2 for Windows Server 2008 SP2 (KB4565583)Security Update for 2010 Microsoft Business Productivity Servers (KB4484460)2020-07 Security Only Update for .NET Framework 4.8 for Windows Server 2012 for x64 (KB4565587)2020-07 Security Only Update for .NET Framework 3.5 for Windows Server 2012 for x64 (KB4565577)2020-07 Security Only Update for .NET Framework 4.8 for Windows 8.1 and Server 2012 R2 for x64 (KB4565588)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows Embedded Standard 7 (KB4565586)Apply update KB4580328 for Microsoft .NET Framework 3.5\4.7.1\4.7.22020-07 Security Only Update for .NET Framework 4.8 for Windows Embedded 8 Standard (KB4565587)2020-07 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server, version 1909 for x64 (KB4565633)2020-07 Security Only Update for .NET Framework 4.8 for Windows 7 (KB4565589)2020-07 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 8.1 (KB4565585)2020-07 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4565508)
Jul 14, 2020Jul 14, 2020
Oracle_linux—
Upgrade dotnet-hostfxr-3.1Upgrade aspnetcore-runtime-3.1Upgrade dotnet-templates-3.1Upgrade dotnet-targeting-pack-3.1Upgrade dotnet-runtime-2.1Upgrade dotnet-sdk-3.1Upgrade dotnet-runtime-3.1Upgrade dotnet-apphost-pack-3.1Upgrade dotnet-sdk-2.1.5xxUpgrade dotnet-sdk-2.1Upgrade dotnetUpgrade netstandard-targeting-pack-2.1Upgrade dotnet-hostUpgrade dotnet-host-fxr-2.1Upgrade aspnetcore-targeting-pack-3.1
Jul 17, 2020Jul 14, 2020
Redhat_linux—
Upgrade dotnet3.1-debugsourceUpgrade dotnet-templates-3.1Upgrade dotnet-sdk-3.1Upgrade dotnet-targeting-pack-3.1Upgrade dotnet-debugsourceUpgrade dotnet-apphost-pack-3.1-debuginfoUpgrade dotnet-host-fxr-2.1-debuginfoUpgrade dotnet-sdk-2.1.5xx-debuginfoUpgrade dotnet-apphost-pack-3.1Upgrade dotnet-sdk-3.1-debuginfoUpgrade netstandard-targeting-pack-2.1Upgrade dotnetUpgrade dotnet3.1-debuginfoUpgrade dotnet-host-fxr-2.1Upgrade dotnet-debuginfoUpgrade dotnet-sdk-2.1Upgrade dotnet-hostfxr-3.1-debuginfoUpgrade dotnet-runtime-3.1Upgrade dotnet-sdk-2.1.5xxUpgrade aspnetcore-targeting-pack-3.1Upgrade aspnetcore-runtime-3.1Upgrade dotnet-hostUpgrade dotnet-runtime-2.1-debuginfoUpgrade dotnet-hostfxr-3.1Upgrade dotnet-runtime-3.1-debuginfoUpgrade dotnet-host-debuginfoUpgrade dotnet-runtime-2.1
Jul 16, 2020Jul 14, 2020
Vmware Photon_os—
Use 'tdnf update' to upgrade all packages to the latest version.
Jul 2, 2025Jul 14, 2020

Prioritise with Active Threat Intelligence

With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.

Explore Intelligence Hub

CVE details

CVSS v4 ScoreN/A
CVSS v3 Score7.8 High
EPSS Score93%
EPSS Percentile100%
In CISA KEV CatalogueTrue

Published

Jul 14, 2020

Metasploit modules

SharePoint DataSet / DataTable Deserialization

References

  • NVD ↗
  • CISA KEV ↗
  • POC In GitHub ↗
    Rapid7
    • The Command Platform

      Respond faster and outpace attackers. Taking command of your attack surface starts here.

      Explore platform
      Capabilities
      • Icon
        Exposure Management
        Identify & remediate at-risk data
      • Attack Surface Management
        Reveal & protect coverage gaps
      • Vulnerability Management
        Pinpoint & eliminate risk
      • Cloud-Native Application Protection
        Discover & defend sensitive data
      • Application Security
        Scan & simplify dev workflows
      • Next-Gen SIEM
        Investigate with AI-driven detections
      • Threat Intelligence Platform
        Recognize & mitigate adversaries
      Explore the platform
      • Start a Free Trial
        TRY NOW
      • AI-Engine
      • Rapid7 Labs
      • Self-Guided Platform Tour
      • Talk to an Expert
      • Rapid7 Threat Intelligence
      All Products
    • MDR Services
      • Managed Detection and Response
        Preemptive MDR that disrupts attackers
      • MDR for Microsoft
        Maximize and protect your Microsoft investment
      • MDR for Enterprise
        Get customized protection for enterprise systems
      • Incident Response Services
        Get help with an active breach
      • Rapid7 vs. Them
        Decide which solution fits
      • Customer Stories
        Read about real benefits
      • MDR Product Tour
        Experience the functionality
      • MDR ROI Calculator
        See how MDR can boost your ROI
      Exposure Management
      • Managed Vulnerability Management
        Get help pinpointing exposures
      • Continuous Red Teaming
        Get help validating exposures
      • Managed Application Security
        Get help securing dev workflows
      • Penetration Testing Services
        Get help with defense assessment
      All services

      MDR Buyer's Guide

      Find the best MDR partner for your business

      READ NOW
    • Threat Alert Center
      • Icon
        Rapid7 Labs
        RESEARCH
        Intelligence, Threat Data & Research
      • Icon
        Emergent Threat Response
        Latest on the blog
      • Icon
        Vulnerability & Exploit Database
        Search thousands of CVEs
      Learn
      • Blog
      • Webinars and Events
      • Resource Library
      • Cybersecurity Fundamentals
      Product
      • Product Documentation
      • Product Release Notes
      • Product Extensions
      • Product Toolkits
      Customer Support
      • Customer Support
      • Rapid7 Forum
    • Partner With Rapid7
      • Partnerships Overview
      • PACT Partner Program
        Expand & enrich customer experience
      • PACT for Service Providers
        Unlock SOC efficiencies
      For Customers
      • Partner Directory
        Find Resellers, MSSPs and Distributors
      • Technology Partners
        Strengthen your security stack
      • AWS Partnership
        Secure AWS resource types
      Partner portal
      • Partner Login
      • Become a Partner
        Develop & win business

      Grow your business

      Security where your customers need it

      Become a partner
    • Company
      • About Us
      • Leadership Team
      • Our Customers
      • Careers
      • Contact Us
      Media
      • Newsroom
      • Awards and Recognition
      • Investors
      In the community
      • Social Good
      • Culture
      • Boston Bruins Partnership
    Request Demo
    Rapid7

    Get Started

    Command Platform
    Exposure Management
    MDR Services
    Solutions

    Take Action

    Start a Free Trial
    Take a Product Tour
    Get Breach Support
    Contact Sales

    Company

    • About Us
    • Leadership
    • Newsroom
    • Our Customers
    • Partner Programs
    • Investors
    • Careers

    Stay Informed

    • Blog
    • Emergent Threat Response
    • Webinars & Events
    • Rapid7 Labs Research
    • Vulnerability Database
    • Security Fundamentals

    For Customers

    • Sign In
    • Support Portal
    • Product Documentation
    • Extension Library
    • Rapid7 Academy
    • Customer Escalation Portal

    Contact Support

    • +1-866-390-8113

    Follow Us

    LinkedIn icon
    LinkedIn
    X (Twitter) icon
    X (Twitter)
    Facebook icon
    Facebook
    Instagram icon
    Instagram
    Bluesky icon
    Bluesky
    © Rapid7
    Legal TermsPrivacy PolicyExport NoticeTrustCookie ListAccessibility Statement