CVE-2020-0899 PUBLISHED CVSS 5.5 MEDIUM

An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'.

EPSS 0.25% · 47.9th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.25%
47.9th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Visual Studio 2019 version 16.5unspecified
MicrosoftMicrosoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)unspecified
MicrosoftMicrosoft Visual Studio 2017 version 15.9 (includes 15.1 - 15.8)unspecified
MicrosoftN/A
microsoftvisual_studio_201715.9
microsoftvisual_studio_201916.0, 16.4, 16.5.0
MicrosoftMicrosoft Visual Studio 201916.0

Timeline

References

Open in Interactive Console →