CVE-2019-1354 is a remote code execution vulnerability affecting Git for Visual Studio 2017 and 2019, stemming from improper input sanitization. This high-severity flaw (CVSS 8.8) can be exploited remotely with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, its high FAUCET Risk Score and mention in media coverage indicate significant potential impact. Community discussion and media attention are limited, but the vulnerability was addressed in Microsoft's December 2019 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.0, < 15.9.18CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.4.1CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.