CVE-2020-1130: fallo de gravedad media en Microsoft Visual Studio 2015 Update 3
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.6epss 0.8%
probabilidad de explotación
0.8%top 46% de las CVE
explotación observada
noninguna fuente lo reporta
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p>
<p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p>
<p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles data operations.</p>
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C
Productos afectados
Microsoft · Microsoft Visual Studio 2015 Update 3Microsoft · Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Microsoft · Microsoft Visual Studio 2019 version 16.0Microsoft · Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)Microsoft · Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)Microsoft · Windows 10 Version 1507Microsoft · Windows 10 Version 1607Microsoft · Windows 10 Version 1709Microsoft · Windows 10 Version 1709 for 32-bit SystemsMicrosoft · Windows 10 Version 1803Microsoft · Windows 10 Version 1809Microsoft · Windows 10 Version 1903 for 32-bit SystemsMicrosoft · Windows 10 Version 1903 for ARM64-based SystemsMicrosoft · Windows 10 Version 1903 for x64-based SystemsMicrosoft · Windows 10 Version 1909Microsoft · Windows 10 Version 2004Microsoft · Windows Server 2016Microsoft · Windows Server 2016 (Server Core installation)Microsoft · Windows Server 2019Microsoft · Windows Server 2019 (Server Core installation)Microsoft · Windows Server, version 1903 (Server Core installation)Microsoft · Windows Server, version 1909 (Server Core installation)Microsoft · Windows Server version 2004CVEs relacionadas — Microsoft Visual Studio 2015 Update 3
En el mismo producto, de las más peligrosas a las menos.
CVE-2020-1147HIGHCVE-2020-1147EPSS 94.0%KEVCVE-2021-36952HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 51.5%CVE-2021-26701HIGH.NET Core Remote Code Execution VulnerabilityEPSS 30.1%CVE-2020-1597—ASP.NET Core Denial of Service VulnerabilityEPSS 6.6%CVE-2020-1108—.NET Core & .NET Framework Denial of Service VulnerabilityEPSS 6.4%CVE-2020-1416—CVE-2020-1416EPSS 5.9%