CVE-2020-26870HighCVSS 7.0

Visual Studio Remote Code Execution Vulnerability

Published
January 12, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Why is a CVE that was issued by the MITRE Corporation in the Security Update Guide? CVE-2020-26870 documents a vulnerability in Cure53 DOMPurify which is open source software used by Visual Studio. The documented Visual Studio updates incorporate the updates in Cure53 DOMPurify which address the vulnerability.

🎯 Affected products5

  • Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
  • Microsoft Visual Studio 2019 version 16.0
  • Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
  • Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
  • Microsoft Visual Studio 2019 version 16.8

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (6)