First published: Thu Mar 12 2020(Updated: )
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Visual Studio Professional 2017 | >=15.1<=15.8 | |
Visual Studio Professional 2019 | >=16.0<=16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0884 is rated as important due to its ability to allow spoofing attacks.
To remediate CVE-2020-0884, update Microsoft Visual Studio to the latest version that addresses this vulnerability.
CVE-2020-0884 affects Microsoft Visual Studio 2017 versions up to 15.8 and Microsoft Visual Studio 2019 versions up to 16.3.
CVE-2020-0884 is a spoofing vulnerability due to the inclusion of an unsecured reply URL.
The potential impact of CVE-2020-0884 includes exposure to phishing attacks, leading to unauthorized access to sensitive information.