CVE-2020-1173 is a spoofing vulnerability affecting Microsoft Power BI Report Server, stemming from improper validation of uploaded attachment content types. With a CVSS score of 6.8 (Medium), an attacker could exploit this by tricking a user into interacting with malicious content, leading to high integrity impact without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, and it has received minimal community discussion and media coverage beyond its initial Patch Tuesday mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:power_bi_report_server:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.