References https://nvd.nist.gov/vuln/detail/CVE-2020-0646 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646 https://support.microsoft.com/zh-cn/topic/2020-%E5%B9%B4-1-%E6%9C%88-14-%E6%97%A5-kb4532937-%E9%80%82%E7%94%A8%E4%BA%8E-windows-10-%E7%89%88%E6%9C%AC-1809-%E5%92%8C-windows-server-2019-%E7%9A%84-net-framework-3-5-%E5%92%8C-4-8-%E7%9A%84%E7%B4%AF%E7%A7%AF%E6%9B%B4%E6%96%B0-5c3845f7-4d2d-fa4f-9b84-ecb7592ce643 http://www.cnvd.org.cn/flaw/show/CNVD-2020-03547 https://www.mdsec.co.uk/2020/01/code-injection-in-workflows-leading-to-sharepoint-rce-cve-2020-0646/ https://avd.aliyun.com/detail?id=AVD-2020-0646 https://www.anquanke.com/post/id/197770 https://rivers.chaitin.cn/blog/cq94ppp0lnechd24404g https://www.4hou.com/index.php/posts/wR4z https://www.tenable.com/cve/CVE-2020-0646 https://www.rapid7.com/db/vulnerabilities/msft-cve-2020-0646/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCCVE-2026-39352: Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path TraversalPoCfrappe-default-login: Frappe Framework - Default Login CredentialsPoCCVE-2025-41242: Spring Framework - Path TraversalPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksPoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)Serverless Framework 未授权 命令注入漏洞PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosureAstro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179)