CVE-2019-1079

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/07/2019
Last modified:
24/08/2020

Description

An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:visual_studio:2010:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2012:update_5:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2013:update_5:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2015:update_3:*:*:*:*:*:*