XML injection in Microsoft products - CVE-2020-1147
Published: July 14, 2020 / Updated: February 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when processing XML data in .NET Framework, Microsoft SharePoint, and Visual Studio. A remote unauthenticated attacker can pass specially crafted XML data to the application and execute arbitrary code on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Microsoft .NET Core
ASP.NET Core MVC
Visual Studio
Microsoft SharePoint Server
rh-dotnet21 (Red Hat package)
rh-dotnet21-dotnet (Red Hat package)
dotnet (Red Hat package)
rh-dotnet31-dotnet (Red Hat package)
dotnet3.1 (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
dotnet-host-fxr-2.1
dotnet-runtime-2.1
dotnet-sdk-2.1
dotnet-sdk-2.1.5xx
dotnet-targeting-pack-3.1
aspnetcore-runtime-3.1
aspnetcore-targeting-pack-3.1
dotnet-apphost-pack-3.1
dotnet-hostfxr-3.1
dotnet-runtime-3.1
dotnet-sdk-3.1
dotnet-sdk-3.1-source-built-artifacts
dotnet-templates-3.1
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
How to mitigate CVE-2020-1147
rh-dotnet21-dotnet (Red Hat package) - update to 2.1.516-1.el7
dotnet (Red Hat package) - addressed in versions 2.1.516-1.el8_0, 2.1.516-1.el8_1, 2.1.516-1.el8_2
rh-dotnet31-dotnet (Red Hat package) - update to 3.1.106-1.el7
dotnet3.1 (Red Hat package) - update to 3.1.106-1.el8_2
dotnet-host-fxr-2.1 - update to 2.1.30-1
dotnet-runtime-2.1 - update to 2.1.30-1
dotnet-sdk-2.1 - update to 2.1.526-1
dotnet-sdk-2.1.5xx - update to 2.1.526-1
dotnet-targeting-pack-3.1 - update to 3.1.26-1.0.1
aspnetcore-runtime-3.1 - update to 3.1.26-1.0.1
aspnetcore-targeting-pack-3.1 - update to 3.1.26-1.0.1
dotnet-apphost-pack-3.1 - update to 3.1.26-1.0.1
dotnet-hostfxr-3.1 - update to 3.1.26-1.0.1
dotnet-runtime-3.1 - update to 3.1.26-1.0.1
dotnet-sdk-3.1 - update to 3.1.420-1.0.1
dotnet-sdk-3.1-source-built-artifacts - update to 3.1.420-1.0.1
dotnet-templates-3.1 - update to 3.1.420-1.0.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Microsoft .NET Framework, SharePoint Server, and Visual Studio
- Red Hat Enterprise Linux 8 update for .NET Core 3.1
- .NET Core on Red Hat Enterprise Linux update for rh-dotnet31-dotnet
- Red Hat Enterprise Linux 8 update for .NET Core
- .NET Core on Red Hat Enterprise Linux update for rh-dotnet21-dotnet
- Red Hat Enterprise Linux 8 update for .NET Core
- Red Hat Enterprise Linux 8 update for .NET Core
- Anolis OS update for dotnet
- Anolis OS update for dotnet3.1