Vulnerabilities > Microsoft > Visual Studio 2019 > 16.4

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2020-1278 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-06-09 CVE-2020-1257 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-06-09 CVE-2020-1203 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-06-09 CVE-2020-1202 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-05-21 CVE-2020-1161 Improper Input Validation vulnerability in Microsoft Asp.Net Core and Visual Studio 2017
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
network
low complexity
microsoft CWE-20
5.0
2020-05-21 CVE-2020-1108 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
network
low complexity
microsoft
7.5
2020-04-15 CVE-2020-0900 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extension Installer Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
3.6
2020-04-15 CVE-2020-0899 Improper Privilege Management vulnerability in Microsoft Visual Studio 2017 and Visual Studio 2019
An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
3.6
2020-03-12 CVE-2020-0789 Link Following vulnerability in Microsoft Visual Studio 2019
A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'.
local
low complexity
microsoft CWE-59
6.6
2020-01-24 CVE-2019-1354 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8