CVE-2020-1416 is an elevation of privilege vulnerability affecting Microsoft Visual Studio, Visual Studio Code, Azure Storage Explorer, and TypeScript, stemming from how they load software dependencies. With a CVSS score of 8.8 (High), it can be exploited remotely with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability if a user is tricked into interacting with a malicious file. While the vulnerability is not listed in CISA's KEV catalog and no public exploit code is available, it has garnered some community discussion and media coverage. Its FAUCET Risk Score of 85/100 indicates a significant risk despite the lack of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_explorer:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:typescript:-:*:*:*:*:*:*:* | ||
>= 15.0, < 15.9.25CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.0.16CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
>= 16.1, < 16.4.11CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.