First published: Mon Jul 15 2019(Updated: )
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio | =2010-sp1 | |
Microsoft Visual Studio | =2012-update_5 | |
Microsoft Visual Studio | =2013-update_5 | |
Microsoft Visual Studio | =2015-update_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1079 is an information disclosure vulnerability that exists in Visual Studio when parsing XML input in certain settings files.
CVE-2019-1079 has a severity rating of 6.5, which is considered medium.
CVE-2019-1079 affects the following versions of Visual Studio: 2010 SP1, 2012 Update 5, 2013 Update 5, and 2015 Update 3.
To fix CVE-2019-1079, Microsoft has released updates for the affected versions of Visual Studio. It is recommended to install these updates to mitigate the vulnerability.
The Common Weakness Enumeration (CWE) ID for CVE-2019-1079 is CWE-20, which represents Improper Input Validation.