CVE-2020-1439

HIGH

SharePoint Server - Remote Code Execution via PerformancePoint Services XML Deserialization

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-20-874/

Scores

CVSS v3 8.8
EPSS 0.2026
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (5)
microsoft/sharepoint_enterprise_server 2013 sp1
microsoft/sharepoint_enterprise_server 2016
microsoft/sharepoint_foundation 2013 sp1
microsoft/sharepoint_server 2010 sp2
microsoft/sharepoint_server 2019
Published Jul 14, 2020
Tracked Since Feb 18, 2026