CVE-2019-1486
published 2019-12-10CVE-2019-1486: A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.48%
71.1th percentile
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2019 | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.4 | — | — |
| microsoft | microsoft_visual_studio_live_share_extension | — | — |
| microsoft | visual_studio_2019 | 16.0 – 16.4 | — |
| microsoft | visual_studio_live_share | < 1.0.1374 | 1.0.1374 |
| msrc | microsoft_visual_studio_2019_version_16.0 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_code_live_share_extension | — | — |
| msrc | microsoft_visual_studio_live_share_extension | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_msrc6.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Visual Studio Live Share Spoofing Vulnerability
vendor_msrc·2019-12-10·CVSS 6.1
CVE-2019-1486 [MEDIUM] Visual Studio Live Share Spoofing Vulnerability
Visual Studio Live Share Spoofing Vulnerability
Description: A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host. An attacker who successfully exploited this vulnerability could cause a connected guest's computer to open a browser and navigate to a URL without consent from the guest.
To exploit the vulnerability, an attacker would need to host a Live Share session and convince a targeted user to connect to the session.
The update addresses the vulnerability by prompting the Live Share guest for consent prior to browsing to the host-specified URL.
FAQ: I want to install the latest supported service baseline for Visual Studio. Do I need to install the previous versions fir
GHSA
GHSA-3xvp-fcxr-3mvq: A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified
ghsa_unreviewed·2022-05-24
CVE-2019-1486 [MEDIUM] CWE-601 GHSA-3xvp-fcxr-3mvq: A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-10
Published