CVE-2020-0789High

Visual Studio Extension Installer Service Denial of Service Vulnerability

Published
March 10, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would allow an attacker to overwrite system files. The update addresses the vulnerability by correcting how the Visual Studio Extension Installer Service handles hard links.

🎯 Affected products2

  • Microsoft Visual Studio 2019 version 16.0
  • Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)