Elevation of Privilege in Microsoft Visual Studio Extension Installer Service
CVE-2020-0900

5.5MEDIUM

What is CVE-2020-0900?

An elevation of privilege vulnerability occurs when the Visual Studio Extension Installer Service fails to correctly handle file operations. This flaw could allow an attacker to execute arbitrary code with elevated privileges on the affected system, potentially compromising sensitive data and system integrity. It is imperative for users to apply the latest updates and security patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Microsoft Visual Studio 2015 Update 3

Microsoft Visual Studio 2017 version 15.9 (includes 15.1 - 15.8) = unspecified

Microsoft Visual Studio 2019 16.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.