cbcvebase.
CVE-2019-0537
published 2019-01-08

CVE-2019-0537: An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file…

PriorityP274medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
7.61%
93.9th percentile
An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_visual_studio
microsoftmicrosoft_visual_studio
microsoftvisual_studio
microsoftvisual_studio
msrcmicrosoft_visual_studio_2010_service_pack_1
msrcmicrosoft_visual_studio_2012_update_5

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger file type for the vulnerability is a malicious .vscontent file opened in Visual Studio
  • Attack vector requires social engineering to deliver a malicious .vscontent file to a developer and have them open it in a vulnerable Visual Studio version
  • Impact is unauthorized file system read access — monitor for Visual Studio processes reading unexpected or sensitive file paths after opening .vscontent files
  • ·No public exploit exists and exploitation is rated 'Less Likely' for both latest and older software releases
  • ·The vulnerability is fixed by correcting how Visual Studio loads .vscontent files; patched builds are referenced via aka.ms/vs/10/release/4476698 and aka.ms/vs/11/release/4476755

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck5.5MEDIUM
vendor_msrc5.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.