---
id: CVE-2020-1024
title: >-
  A remote code execution vulnerability exists in Microsoft SharePoint when the
  software fails to check the source markup of an application package
summary: >-
  A remote code execution vulnerability exists in Microsoft SharePoint when the
  software fails to check the source markup of an application package. An
  attacker who successfully exploited the vulnerability could run arbitrary code
  in the c…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: microsoft
product: sharepoint_enterprise_server
affected:
  - sharepoint_enterprise_server = 2016
  - sharepoint_foundation = 2013
  - sharepoint_server = 2019
published: '2020-05-21'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1024'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1024'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1024
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03718
epssPercentile: 0.8931
ingestedAt: '2026-08-19T17:42:36.182Z'
---

## Overview

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.
The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.

## Affected

- `sharepoint_enterprise_server = 2016`
- `sharepoint_foundation = 2013`
- `sharepoint_server = 2019`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
