8.8
CVE-2020-1181
- EPSS 69.3%
- Veröffentlicht 09.06.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:55
- Erkennungen
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Sharepoint Enterprise Server Version 2016
Microsoft ≫ Sharepoint Foundation Version 2010 Update sp2
Microsoft ≫ Sharepoint Foundation Version 2013 Update sp1
Microsoft ≫ Sharepoint Server Version 2019
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 69.3% | 0.993 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1181
https://www.zerodayinitiative.com/advisories/ZDI-20-694/