CVE-2020-1181 describes a remote code execution vulnerability in Microsoft SharePoint Server, SharePoint Foundation, and SharePoint Enterprise Server. This flaw arises from the server's failure to properly identify and filter unsafe ASP.Net web controls. It carries a CVSS score of 8.8 (HIGH), indicating a network-based attack with low privileges, no user interaction required, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score suggest a significant threat. Although no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available, community discussion, including a Reddit post with a step-by-step Proof of Concept, indicates active interest and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.