CVE-2020-0900 is an elevation of privilege vulnerability affecting Microsoft Visual Studio 2015, 2017, and 2019, stemming from improper file operations within the Visual Studio Extension Installer Service. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and capable of high integrity impact without user interaction. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, and community discussion and media coverage are minimal, though it was mentioned in a BleepingComputer article regarding Microsoft's April 2020 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
update_3CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2015:update_3:*:*:*:*:*:*:* | ||
15.9CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:16.0:*:*:*:*:*:*:* | ||
16.4CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:16.4:*:*:*:*:*:*:* | ||
16.5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:16.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.