Learn about CVE-2020-1200 affecting Microsoft SharePoint Server 2016, 2019, Foundation 2010, and 2013. Discover the impact, technical details, and mitigation steps for this high-severity remote code execution vulnerability.
Microsoft SharePoint Remote Code Execution Vulnerability was published on 2020-09-08. It affects various versions of Microsoft SharePoint including SharePoint Server 2016, SharePoint Server 2019, SharePoint Foundation 2010, and SharePoint Foundation 2013.
Understanding CVE-2020-1200
A critical remote code execution vulnerability in Microsoft SharePoint allows attackers to execute arbitrary code in the context of the SharePoint application pool and server farm account.
What is CVE-2020-1200?
The vulnerability arises from a failure to check the source markup of SharePoint application packages.
Attackers can exploit the flaw by uploading a specially crafted application package to the affected SharePoint version.
A security update has been released to address this issue.