Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-1147

Description

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

POC

Reference

- http://packetstormsecurity.com/files/158694/SharePoint-DataSet-DataTable-Deserialization.html

- http://packetstormsecurity.com/files/158876/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html

- http://packetstormsecurity.com/files/163644/Microsoft-SharePoint-Server-2019-Remote-Code-Execution.html

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ARPSyndicate/kenzer-templates

- https://github.com/Deep-Bagchi/ysoserial.net

- https://github.com/Elsfa7-110/kenzer-templates

- https://github.com/H0j3n/EzpzSharepoint

- https://github.com/Ostorlab/KEV

- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors

- https://github.com/SohelParashar/.Net-Deserialization-Cheat-Sheet

- https://github.com/amcai/myscan

- https://github.com/d4n-sec/d4n-sec.github.io

- https://github.com/hktalent/ysoserial.net

- https://github.com/irsdl/ysonet

- https://github.com/lgturatti/techdrops

- https://github.com/merlinepedra/nuclei-templates

- https://github.com/merlinepedra25/nuclei-templates

- https://github.com/michael101096/cs2020_msels

- https://github.com/puckiestyle/ysoserial.net

- https://github.com/pwntester/ysoserial.net

- https://github.com/secret-arrow/ysoserial.net

- https://github.com/sobinge/nuclei-templates