Details are now available on how to exploit a critical security vulnerability affecting Microsoft SharePoint, increasing the risk of attacks on unpatched systems.
A technical post released this week explains how the flaw works and how a low- privileged can exploit it to remotely execute arbitrary code on a targeted SharePoint server.

The flaw, identified as CVE-2020-1147 (severity 9.8 out of 10), also affects the .NET Framework and Visual Studio. Microsoft released a fix in this month's security update release.
Security researcher Steven Seeley provides a complete analysis of the root causes of the issue and how it can be exploited to achieve remote code execution on a vulnerable SharePoint server.
Essentially, the flaw is a failure to check the source signal of the input XML file, allowing an attacker to execute arbitrary code within the process responsible for de-synthesizing XML content.
On his website, Seeley walks through all the steps required to create the code that allows a system and abuse the controls that allow it to do so remotely.
Seeley's analysis is intended to help "understand the underlying technology." It can be used to create a fully functional attack scenario, but it does not provide an exploit that can be used to deploy an attack.
However, organizations should prioritize applying the patch. Microsoft's exploitability assessment is that CVE-2020-1147 is an attractive target for threat actors, who could exploit it consistently.
“Microsoft rates this bug with an exploitability rating of 1, which means you should fix it immediately if you haven’t done so. It’s very likely that this “gadget chain” can be used in many applications built with .net, and even if you don’t have SharePoint server installed, you are still affected by this bug,” says Steven Seeley.
Ben Hawkes, head of Google's Project Zero security research team, argues that this issue is bigger than the publicly disclosed Windows DNS vulnerability.
Microsoft says that the vulnerability, CVE-2020-1147, was discovered by Oleksandr Mirosh of Micro Focus Fortify, Jonathan Birch of the Microsoft Office Security Team, and Markus Wulftange. They found and reported the vulnerability independently.
