Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1147

Опубликовано: 14 июл. 2020
Источник: redhat
CVSS3: 8.8
EPSS Критический

Описание

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

It was discovered that .NET Core did not properly check the source markup of XML files. A remote, unauthenticated attacker could possibly exploit this flaw to execute arbitrary code by sending specially crafted requests to an application parsing certain kinds of XML files or an ASP.NET Core application.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1856929dotnet: XML source markup processing remote code execution

EPSS

Процентиль: 100%
0.9343
Критический

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

msrc
больше 5 лет назад

.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability

CVSS3: 7.8
github
больше 3 лет назад

.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability

oracle-oval
больше 5 лет назад

ELSA-2020-2954: .NET Core 3.1 security and bugfix update (CRITICAL)

oracle-oval
больше 5 лет назад

ELSA-2020-2938: .NET Core security and bugfix update (CRITICAL)

EPSS

Процентиль: 100%
0.9343
Критический

8.8 High

CVSS3