{ "id": "CVE-2020-1416", "sourceIdentifier": "secure@microsoft.com", "published": "2020-07-14T23:15:17.760", "lastModified": "2023-03-09T18:02:29.547", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'." }, { "lang": "es", "value": "Se presenta una vulnerabilidad de elevaci\u00f3n de privilegios en Visual Studio y Visual Studio Code cuando cargan dependencias de software, tambi\u00e9n se conoce como \"Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 9.3 }, "baseSeverity": "HIGH", "exploitabilityScore": 8.6, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-269" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:azure_storage_explorer:-:*:*:*:*:*:*:*", "matchCriteriaId": "334D89E1-AD97-4FB3-A6F1-15DCCFDBE633" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:typescript:-:*:*:*:*:*:*:*", "matchCriteriaId": "BA277009-E2BA-4587-A128-B3945124B804" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*", "versionStartIncluding": "15.0", "versionEndExcluding": "15.9.25", "matchCriteriaId": "A73D1417-E2B9-4ECD-B637-46D22B21F229" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*", "versionStartIncluding": "16.0", "versionEndExcluding": "16.0.16", "matchCriteriaId": "E94E13B1-8CE6-4B86-AB58-19FAB3F92E05" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*", "versionStartIncluding": "16.1", "versionEndExcluding": "16.4.11", "matchCriteriaId": "0646F955-A55C-4DA7-A73A-0A23B51FB47C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*", "versionStartIncluding": "16.5", "versionEndExcluding": "16.6.4", "matchCriteriaId": "F639AE14-5A14-4CFC-B2AF-AC0B458F2F14" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*", "versionEndExcluding": "1.47.1", "matchCriteriaId": "39A9B2C7-91A5-4720-98E5-33A633E7EAB2" } ] } ] } ], "references": [ { "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1416", "source": "secure@microsoft.com", "tags": [ "Patch", "Vendor Advisory" ] } ] }