CVE Vulnerabilities

CVE-2020-0900

Improper Privilege Management

Published: Apr 15, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka ‘Visual Studio Extension Installer Service Elevation of Privilege Vulnerability’.

Weakness

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Visual_studio_2015 Microsoft update_3 update_3
Visual_studio_2017 Microsoft 15.9 15.9
Visual_studio_2019 Microsoft 16.0 16.0
Visual_studio_2019 Microsoft 16.4 16.4
Visual_studio_2019 Microsoft 16.5.0 16.5.0

Potential Mitigations

References