CVE-2019-1486High
Visual Studio Live Share Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host. An attacker who successfully exploited this vulnerability could cause a connected guest's computer to open a browser and navigate to a URL without consent from the guest. To exploit the vulnerability, an attacker would need to host a Live Share session and convince a targeted user to connect to the session. The update addresses the vulnerability by prompting the Live Share guest for consent prior to browsing to the host-specified URL.
🎯 Affected products4
- Microsoft Visual Studio 2019 version 16.0
- Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
- Microsoft Visual Studio Code Live Share extension
- Microsoft Visual Studio Live Share extension
✅ Remediation
KBRelease Notes (Security Update)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1486
- patchhttps://aka.ms/vs/16/release/latest
- patchhttps://marketplace.visualstudio.com/items?itemName=MS-vsliveshare.vsls-vs
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.0
- patchhttps://marketplace.visualstudio.com/items?itemName=MS-vsliveshare.vsliveshare