First published: Tue Nov 12 2019(Updated: )
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio 2017 | =15.9 | |
Microsoft Visual Studio 2019 | =16.0 | |
Microsoft Visual Studio 2019 | =16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1425 is an elevation of privilege vulnerability in Visual Studio.
CVE-2019-1425 affects Microsoft Visual Studio 2017 version 15.9, Microsoft Visual Studio 2019 version 16.0, and Microsoft Visual Studio 2019 version 16.3.
The severity of CVE-2019-1425 is medium with a CVSS score of 6.5.
To fix CVE-2019-1425, update Microsoft Visual Studio to the latest version.
More information about CVE-2019-1425 can be found at the following link: [CVE-2019-1425](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1425).