CVE-2020-1393
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/07/2020
Last modified:
21/07/2021
Description
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:visual_studio:2015:update_3:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* | 15.0 (including) | 15.9.25 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | 16.0 (including) | 16.4.11 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | 16.5.0 (including) | 16.6.4 (excluding) |
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page