CVE-2019-0727 is an elevation of privilege vulnerability affecting Microsoft Visual Studio and Windows operating systems, specifically within the Diagnostics Hub Standard Collector or Visual Studio Standard Collector. An attacker with local access could exploit this flaw to delete files in arbitrary locations. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires local user privileges, but can lead to high impact on confidentiality, integrity, and availability. There is no known public exploit code or Metasploit module available, and it is not on CISA's Known Exploited Vulnerabilities catalog, indicating it is not actively exploited. Community discussion and media coverage are minimal, with only one article mentioning it as part of a larger patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio:2015:update3:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:15.0:*:*:*:*:*:*:* | ||
15.9CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:16.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.