CVE Vulnerabilities

CVE-2020-1147

Published: Jul 14, 2020 | Modified: Oct 29, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
.net_coreMicrosoft2.1 (including)2.1 (including)
.net_coreMicrosoft3.1 (including)3.1 (including)
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet21-0:2.1-19.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet21-dotnet-0:2.1.516-1.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet31-dotnet-0:3.1.106-1.el7*
Red Hat Enterprise Linux 8RedHatdotnet-0:2.1.516-1.el8_2*
Red Hat Enterprise Linux 8RedHatdotnet3.1-0:3.1.106-1.el8_2*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatdotnet-0:2.1.516-1.el8_0*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatdotnet-0:2.1.516-1.el8_1*

References