CVE-2020-1147 is a remote code execution vulnerability affecting Microsoft .NET Framework, Microsoft SharePoint Server, and Visual Studio. The flaw is caused by improper validation of XML file input and failure to safely check source markup before processing attacker-controlled XML content. Available technical reporting ties exploitation in SharePoint to unsafe handling of serialized data embedded in XML-based inputs, enabling deserialization-driven code execution paths. In SharePoint exploitation scenarios, the vulnerability has been associated with attacker-supplied DataSet content that is processed by vulnerable application logic, ultimately allowing execution of attacker-controlled code when malicious markup is accepted and deserialized.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module targeting Microsoft SharePoint servers vulnerable to CVE-2020-1147, a remote code execution flaw due to unsafe XML deserialization in the DataSet/DataTable classes. The exploit requires valid domain user credentials and targets the '/_layouts/15/quicklinks.aspx' endpoint, abusing the 'Mode=Suggestion' parameter to deliver a maliciously crafted XML payload. The module supports multiple payload types, including Windows command execution, EXE dropper, and PowerShell, leveraging Metasploit's payload framework. The exploit is weaponized, providing reliable remote code execution as the SharePoint application service account. The code is well-structured, with clear separation of check and exploit logic, and uses Metasploit's HttpClient and CmdStager mixins for network communication and payload delivery. The only fingerprintable endpoint is the SharePoint quicklinks page, which is used both for detection and exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older .NET Framework/SharePoint/Visual Studio remote code execution vulnerability whose exploit is described as nearly identical to the CVE-2025-49704/CVE-2025-53770 exploit chain.
A SharePoint deserialization-based remote code execution vulnerability that can be exploited to execute code and deploy in-memory or virtual web shells, including via YSoSerial.Net payloads.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.