A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2020-1147

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Published
2021-11-03
Modified
2026-07-31
Sources
cisa-kev

Summary

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.