CVE-2020-1102 is a remote code execution vulnerability in Microsoft SharePoint Enterprise Server and SharePoint Server. It arises from the software's failure to properly validate the source markup of application packages, allowing an attacker to execute arbitrary code. With a CVSS score of 8.8 (High), this vulnerability can be exploited remotely with low privileges and no user interaction, leading to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, indicating high awareness despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.