<?xml version="1.0" encoding="UTF-8" ?><!-- generator=Zoho Sites --><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><atom:link href="https://www.gtconsult.com/blogs/tag/cve/feed" rel="self" type="application/rss+xml"/><title>GTconsult - Blog #CVE</title><description>GTconsult - Blog #CVE</description><link>https://www.gtconsult.com/blogs/tag/cve</link><lastBuildDate>Thu, 03 Sep 2026 00:51:32 -0700</lastBuildDate><generator>http://zoho.com/sites/</generator><item><title><![CDATA[You Don't Wait for Something to Look Dangerous Before You Take It Seriously]]></title><link>https://www.gtconsult.com/blogs/post/you-don-t-wait-for-something-to-look-dangerous-before-you-take-it-seriously</link><description><![CDATA[<img align="left" hspace="5" src="https://www.gtconsult.com/Blog Site/Black White Geometric Talk Podcast YouTube Thumbnail -1-.png"/>The best security and IT decisions get made before a risk looks dangerous to everyone, not after. Here's what that looks like, with a real example.]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_2xxg23QISMyRVJT8xzT-ag" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_X3_6N0H-TXiwOm9LpfamUQ" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm__y66C0gJSa683zUw9Xpm_w" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_ki6DL9HYHnJ7ndrSXQ-y7g" data-element-type="image" class="zpelement zpelem-image "><style> @media (min-width: 992px) { [data-element-id="elm_ki6DL9HYHnJ7ndrSXQ-y7g"] .zpimage-container figure img { width: 962px ; height: 505.05px ; } } </style><div data-caption-color="" data-size-tablet="" data-size-mobile="" data-align="center" data-tablet-image-separate="false" data-mobile-image-separate="false" class="zpimage-container zpimage-align-center zpimage-tablet-align-center zpimage-mobile-align-center zpimage-size-fit zpimage-tablet-fallback-fit zpimage-mobile-fallback-fit hb-lightbox " data-lightbox-options="
                type:fullscreen,
                theme:dark"><figure role="none" class="zpimage-data-ref"><span class="zpimage-anchor" role="link" tabindex="0" aria-label="Open Lightbox" style="cursor:pointer;"><picture><img class="zpimage zpimage-style-none zpimage-space-none " src="/Blog%20Site/Black%20White%20Geometric%20Talk%20Podcast%20YouTube%20Thumbnail%20-1-.png" size="fit" data-lightbox="true"/></picture></span></figure></div>
</div></div></div></div></div><div data-element-id="elm_QK_KcnRmPstH733TQmkpfQ" data-element-type="section" class="zpsection zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_1YxEJEZmbhvroinAV1LIsw" data-element-type="row" class="zprow zprow-container zpalign-items-flex-start zpjustify-content-flex-start zpdefault-section zpdefault-section-bg " data-equal-column="false"><style type="text/css"></style><div data-element-id="elm_E4JEPSDt4E1Xtqpqj0SiNQ" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_pnPRCQ6LSJaklwpaAmKSzg" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center zptext-align-mobile-center zptext-align-tablet-center " data-editor="true"><p></p><div><p style="text-align:left;">You don't wait for something to look dangerous before you take it seriously. You take it seriously because someone qualified already has.</p><p style="text-align:left;">That's a small idea with a lot riding on it. Most of the costly mistakes we see in IT and security don't happen because nobody knew about a risk. They happen because the risk didn't look urgent yet, so it sat at the bottom of a list until it did.</p></div><p></p></div>
</div><div data-element-id="elm_nsqfXFXrkdX7xhw2BjBk5g" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:26px;"><strong>Visible danger is a lagging signal</strong></span></h2></div>
<div data-element-id="elm_FeGkr55ebZ2zcNVmykSoYQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>By the time a risk is obvious to everyone in a room, it's usually already been a risk for a while. Obvious is late. The people who actually understand a system, a contract, or a process can typically see a problem taking shape long before it's loud enough for everyone else to notice from the outside.</p><p>That gap, between when a real risk starts and when it becomes visible to a non-specialist, is exactly where the damage happens. Waiting for the visible version of a problem before acting on it isn't caution, it's just later.</p></div><p></p></div>
</div></div></div></div></div><div data-element-id="elm_IioQ-2tu3bwMrQePefzH-A" data-element-type="section" class="zpsection zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_oxP4JScn_rOJsL4OZ6Op9A" data-element-type="row" class="zprow zprow-container zpalign-items-flex-start zpjustify-content-flex-start zpdefault-section zpdefault-section-bg " data-equal-column="false"><style type="text/css"></style><div data-element-id="elm_qlIf_k7A4uCxHsbC-t8Krg" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_psx-fgFac9jXdeWCNxT-AQ" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:26px;"><strong><span>What &quot;qualified&quot; is actually for</span></strong></span></h2></div>
<div data-element-id="elm_liziePK9O8ASOTsZx-7s_Q" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>A good partner isn't the one who reacts fastest once something's on fire. It's the one who was already watching, who flagged the issue before it needed flagging urgently, and who already had a plan in place before you needed one.</p><p>That's a genuinely different skill from incident response. It's not about being fast when things go wrong. It's about noticing quietly, consistently, before things go wrong, and being trusted enough that &quot;this needs attention&quot; is taken seriously the first time it's said, not the third.</p></div><p></p></div>
</div></div></div></div></div><div data-element-id="elm_GmY01AupdhYVWlm9cn-_jQ" data-element-type="section" class="zpsection zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_WHQdWrljb0Bq3i_RUbfMMw" data-element-type="row" class="zprow zprow-container zpalign-items-flex-start zpjustify-content-flex-start zpdefault-section zpdefault-section-bg " data-equal-column="false"><style type="text/css"></style><div data-element-id="elm_8BFbv4SJSfj4z329qOgGXw" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_lNmp0kHbc6hTtM0q1TykCg" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:26px;"><strong><span>A recent example</span></strong></span></h2></div>
</div></div></div></div><div data-element-id="elm_mePHs5-xIfUjhn3XPxoLxw" data-element-type="section" class="zpsection zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_kD-3-aoDviZZ8kEIz9PiQw" data-element-type="row" class="zprow zprow-container zpalign-items-center zpjustify-content-flex-start " data-equal-column="false"><style type="text/css"></style><div data-element-id="elm_jl_AbbLoBlrw2FC4F53O3w" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-6 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_qtSVEYwIRD7uHvQo_PutEg" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>A few weeks ago, we flagged a SharePoint vulnerability scoring 9.8 out of 10, CVE-2026-20963, before most organisations running it had any real reason to think about it. It wasn't an old, deprecated version being targeted either. It affected every supported on-premises SharePoint version at once: Subscription Edition, 2019, and 2016.</p><p><br/></p><p>Microsoft shipped a patch for it in January 2026. For two months, that patch just sat there, available, unremarkable, one line in a long list of monthly updates. Then on 18 March, the U.S. Cybersecurity and Infrastructure Security Agency added it to their Known Exploited Vulnerabilities catalog, confirming that attackers were actively using it against real environments.</p></div><p></p></div>
</div></div><div data-element-id="elm_Rapi7hKCk_aC63PJzZ_uhQ" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-6 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_2TojXxllESII66meaeuoTA" data-element-type="video" class="zpelement zpelem-video "><style type="text/css"> @media (max-width: 767px) { [data-element-id="elm_2TojXxllESII66meaeuoTA"].zpelem-video iframe.zpvideo{ width:560px !important; height:315px !important; } } @media all and (min-width: 768px) and (max-width:991px){ [data-element-id="elm_2TojXxllESII66meaeuoTA"].zpelem-video iframe.zpvideo{ width:560px !important; height:315px !important; } } </style><div class="zpvideo-container zpiframe-align-left zpiframe-mobile-align-center zpiframe-tablet-align-center"><iframe class="zpvideo " width="560" height="257" src="https://www.youtube.com/embed/q2uThhTkZv4?si=0yMAvCJS7Ce6OnSy" frameborder="0" allowfullscreen></iframe></div>
</div></div></div><div data-element-id="elm_4QwPhF-MjYV-FWFBpcCG1g" data-element-type="row" class="zprow zprow-container zpalign-items-flex-start zpjustify-content-flex-start zpdefault-section zpdefault-section-bg " data-equal-column="false"><style type="text/css"></style><div data-element-id="elm_i4NCzeueLzifQ45AXMs7UA" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_ux3Po_T2_J6rw-ut_MT3Tg" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>Here's the part worth sitting with: nothing about the vulnerability changed between January and March. The danger was exactly as real in January as it was in March. The only thing that changed was that by March, it was finally visible enough to make headlines.</p><p><br/></p><p>Acting on it in January meant taking it seriously before it looked dangerous. Acting on it in March meant taking it seriously once everyone else already had to.</p></div><p></p></div>
</div></div></div></div></div><div data-element-id="elm_HRVmeRzuUNx_m0nqe_3OyA" data-element-type="section" class="zpsection zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_UPPBxPyYglMKAYQsKRb4RQ" data-element-type="row" class="zprow zprow-container zpalign-items-flex-start zpjustify-content-flex-start zpdefault-section zpdefault-section-bg " data-equal-column="false"><style type="text/css"></style><div data-element-id="elm_C1JK33VfyvPCTsN9GfQXNQ" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- zpdefault-section zpdefault-section-bg "><style type="text/css"></style><div data-element-id="elm_rZpfFNSFv_lryeVySYpAWA" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:26px;"><span><strong>Why this matters beyond one CVE</strong></span></span></h2></div>
<div data-element-id="elm_Z2z4hgQi3QXENo43ivwNnA" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>This pattern isn't specific to SharePoint, or to security. It shows up anywhere risk quietly builds before it's acknowledged: a contract clause nobody double-checked, a permission structure that's grown looser over years, a process that's one departure away from breaking. In every case, the actual danger and the visible danger arrive at different times, and the gap between them is where a good partner earns their keep.</p><p><br/></p><p>The standard worth holding any technology or security partner to isn't &quot;how quickly do you respond when something breaks.&quot; It's &quot;what have you already flagged that hasn't broken yet.&quot;</p></div><p></p></div>
</div><div data-element-id="elm_Kub-Zeh5RBDO6KKVe5lYQQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>Want a partner who's watching before things get loud? <a href="/contact" title="Get in touch" rel="">Get in touch</a> and we'll show you what we're already keeping an eye on.</p></div><p></p></div>
</div><div data-element-id="elm_Rr2H2VlsJvQeWO6ym83scQ" data-element-type="button" class="zpelement zpelem-button "><style></style><div class="zpbutton-container zpbutton-align-center zpbutton-align-mobile-center zpbutton-align-tablet-center"><style type="text/css"></style><a class="zpbutton-wrapper zpbutton zpbutton-type-primary zpbutton-size-md zpbutton-style-oval " href="/contact" target="_blank"><span class="zpbutton-content">Get in Touch</span></a></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Wed, 02 Sep 2026 15:44:33 +0000</pubDate></item><item><title><![CDATA[SharePoint CVE-2020-1147]]></title><link>https://www.gtconsult.com/blogs/post/SharePoint-CVE-2020-1147</link><description><![CDATA[<img align="left" hspace="5" src="https://www.gtconsult.com/Blog Site/SharePoint-CVE-2020-1147.jpg"/>Microsoft has released a patch to fix CVE-2020-1147 which they have described as following. “A remote code execution vulnerability exists in .NET Frame ]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_XXjIwd4UR9mZiSs6l8W84A" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_-aovkdn3QiWPdbz2Oh8K8A" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_ac5vMkZDT0K2V5r3MAOpSw" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_KVN3MHD6ROK3kJtYFHlfJA" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-align-center " data-editor="true"><span style="color:inherit;"><p><span style="font-size:32px;">SharePoint CVE-2020-1147 now has a PoC</span></p></span></h2></div>
<div data-element-id="elm_D_tyqCoQTJuG4bpJ4LVuWA" data-element-type="text" class="zpelement zpelem-text "><style> [data-element-id="elm_D_tyqCoQTJuG4bpJ4LVuWA"].zpelem-text { border-radius:1px; } </style><div class="zptext zptext-align-center " data-editor="true"><p style="text-align:left;"><span style="font-size:16px;">Microsoft has released a patch to fix <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1147" target="_blank" rel="">CVE-2020-1147</a> which they have described as following.</span></p><p style="text-align:left;"><span style="font-size:16px;">“A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content.</span></p><p style="text-align:left;"><span style="font-size:16px;">To exploit this vulnerability, an attacker could upload a specially crafted document to a server utilizing an affected product to process content.”</span></p><p style="text-align:left;"><span style="font-size:16px;">&nbsp;</span></p><p style="text-align:left;"><span style="font-size:16px;">Basically,&nbsp;<span style="color:inherit;text-align:center;">low privileged user&nbsp;</span>who knows what they are doing can get remote code execution on the SharePoint server.&nbsp; Technically you don’t even need SharePoint running as it affects .Net applications, so it’s a pretty big issue.&nbsp;</span></p><p style="text-align:left;"><span style="font-size:16px;">&nbsp;</span></p><p style="text-align:left;"><span style="font-size:16px;">The bug was discovered by <em><a href="https://twitter.com/olekmirosh" title="Oleksandr Mirosh" target="_blank" rel="">Oleksandr Mirosh</a>,&nbsp;<a href="https://twitter.com/mwulftange" target="_blank" rel="">Markus Wulftange</a>&nbsp;and&nbsp;<a href="https://www.linkedin.com/in/jonathan-birch-ab27681/" target="_blank" rel="">Jonathan Birch</a></em><em> and you can check out the <a href="https://srcincite.io/blog/2020/07/20/sharepoint-and-pwn-remote-code-execution-against-sharepoint-server-abusing-dataset.html" target="_blank" rel="">PoC</a> if you really want to understand more.</em></span></p><p style="text-align:left;"><span style="font-size:16px;">&nbsp;</span></p><p style="text-align:left;"><span style="font-size:16px;">I would recommend that everyone gets to patching ASAP as this could be used for lateral movement and privilege escalation to gain domain control.</span></p><p style="text-align:left;"><span style="font-size:16px;">&nbsp;</span></p><p><span style="color:inherit;font-size:16px;"></span></p><p style="text-align:left;"><span style="font-size:16px;">If your business has an <a href="https://www.gtconsult.com/support">A Team Support agreement</a> you have already been patched.</span></p></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Tue, 21 Jul 2020 11:12:36 +0000</pubDate></item></channel></rss>