CVE-2020-1130

medium Microsoft
CVSS v3 Base Score
6.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
EPSS Score
0.5%
Exploitation probability in 30 days
Top 35% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
Low
Availability
Low
Published: September 11, 2020 (2071 days ago)
Last Modified: February 23, 2026
Vendor: Microsoft

Description

<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p> <p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles data operations.</p>

CWE

NVD-CWE-noinfo

Affected Products

microsoft visual studiomicrosoft visual studio 2017microsoft visual studio 2019microsoft windows 10microsoft windows server 2016microsoft windows server 2019

References