High severity8.8NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026
CVE-2020-1439
CVE-2020-1439
Description
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 2013 Service Pack 1
- (no CPE)range: 2019
cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*
- (no CPE)range: 2013 Service Pack 1
Patches
Vulnerability mechanics
References
2- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1439nvdPatchVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-20-874/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.