CVE-2020-1200 is a remote code execution vulnerability in Microsoft SharePoint (Enterprise Server, Foundation, and Server) that arises from insufficient validation of application package source markup. An unauthenticated attacker could exploit this by uploading a specially crafted SharePoint application package, leading to arbitrary code execution in the context of the SharePoint application pool and server farm account. This vulnerability has a high CVSS score of 8.6, indicating a severe risk with a network attack vector and low attack complexity. Successful exploitation could result in significant impact to confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV or Hot List) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability garnered substantial community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.