CVE-2019-1079: Input Validation
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-1079?
CVE-2019-1079 is an information disclosure vulnerability that exists in Visual Studio when parsing XML input in certain settings files.
How severe is CVE-2019-1079?
CVE-2019-1079 has a severity rating of 6.5, which is considered medium.
Which versions of Visual Studio are affected by CVE-2019-1079?
CVE-2019-1079 affects the following versions of Visual Studio: 2010 SP1, 2012 Update 5, 2013 Update 5, and 2015 Update 3.
How can I fix CVE-2019-1079?
To fix CVE-2019-1079, Microsoft has released updates for the affected versions of Visual Studio. It is recommended to install these updates to mitigate the vulnerability.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-1079?
The Common Weakness Enumeration (CWE) ID for CVE-2019-1079 is CWE-20, which represents Improper Input Validation.