CVE-2020-1416

Severity
8.8HIGH
EPSS
9.9%
top 7.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages10 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-76cm-vv6x-f8wv: An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Vi2022-05-24
CVEList
CVE-2020-1416: An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Vi2020-07-14

📋Vendor Advisories

1
Microsoft
Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability2020-07-14

💬Community

3
Bugzilla
CVE-2020-1925 olingo-odata: Server side request forgery in AsyncResponseWrapperImpl2020-01-13
Bugzilla
CVE-2019-15225 envoy: crafted request with long URI allows remote attacker to cause denial of service2019-10-25
Bugzilla
CVE-2019-14993 istio/envoy: mishandling regular expressions for long URIs leading to DoS2019-10-09
CVE-2020-1416 (HIGH CVSS 8.8) | An elevation of privilege vulnerabi | cvebase.io