CVE-2020-1416
Description
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability.
Risk Information
Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
10.088
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2020-1416 are affected in Microsoft Visual Studio Code (x64) 1.47.0 | Windows |
| Vulnerabilities CVE-2020-1416 are affected in Microsoft Visual Studio Code 1.47.0 | Windows |
| Vulnerabilities CVE-2020-1416 are affected in Microsoft Visual Studio Community 2019 16.0.15 | Windows |
| Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Community 2019 16.4.10 | Windows |
| Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Community 2019 16.6.3 | Windows |
| Vulnerabilities CVE-2020-1416 are affected in Microsoft Visual Studio Enterprise 2019 16.0.15 | Windows |
| Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Enterprise 2019 16.4.10 | Windows |
| Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Enterprise 2019 16.6.3 | Windows |
| Vulnerabilities CVE-2020-1416 are affected in Microsoft Visual Studio Professional 2019 16.0.15 | Windows |
| Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Professional 2019 16.4.10 | Windows |
| Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Professional 2019 16.6.3 | Windows |
| Vulnerabilities CVE-2020-1416 are affected in Microsoft Visual Studio Code (User Based) 1.47.0 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-334124 | Microsoft Visual Studio Code (x64) (1.84.1) |
| PATCH-333564 | Microsoft Visual Studio Code (1.83.1) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234