CVE-2020-1133: Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p> <p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles file operations.</p>
Other sources
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1130.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1133?
The severity of CVE-2020-1133 is high with a CVSS score of 7.8.
Which software products are affected by CVE-2020-1133?
The affected software products include Microsoft Visual Studio 2015 Update 3, Microsoft Visual Studio 2017 (versions 15.0 to 15.9.27), Microsoft Visual Studio 2019 (versions 16.0 to 16.4.13), Microsoft Windows 10 (versions 1607 to 2004), Microsoft Windows Server 2016 (versions 1903 to 2004), and Microsoft Windows Server 2019.
What is the vulnerability description of CVE-2020-1133?
CVE-2020-1133 is an elevation of privilege vulnerability that exists in the Diagnostics Hub Standard Collector, where it improperly handles file operations.
How can I fix CVE-2020-1133?
To fix CVE-2020-1133, it is recommended to apply the latest security updates provided by Microsoft for the affected software products.
Where can I find more information about CVE-2020-1133?
You can find more information about CVE-2020-1133 on the Microsoft Security Guidance advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1133