CVE-2020-0810 is an elevation of privilege vulnerability affecting Microsoft Visual Studio versions 2015, 2017, and 2019, as well as Windows 10, Windows Server 2016, and Windows Server 2019. It allows the Diagnostics Hub Standard Collector or Visual Studio Standard Collector to create files in arbitrary locations. With a CVSS score of 7.8 (High), an attacker with local access can run a specially crafted application to exploit this vulnerability, leading to high impact on confidentiality, integrity, and availability of the system. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2015:-:update3:*:*:*:*:*:* | ||
>= 15.1, <= 15.9CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* | ||
>= 16.0, <= 16.4CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.