July 21, 2020
HC3 Sector Alert: CVE-2020-1147: .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
On July 14, 2020, Microsoft released a patch for CVE-2020-1147. If left unpatched the vulnerability, which affects Microsoft SharePoint, .NET Framework, and Visual Studio, could allow an attacker to run arbitrary code. According to Microsoft, this type of vulnerability is historically exploited by attackers. To patch the vulnerability, the most recent software needs to be installed for the affected programs. This vulnerability should be carefully considered for patching by any healthcare organization with special consideration to the vulnerability criticality category against the risk management posture of the organization.