CVE-2020-1133

medium Microsoft
CVSS v3 Base Score
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.4%
Exploitation probability in 30 days
Top 39% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: September 11, 2020 (2071 days ago)
Last Modified: February 23, 2026
Vendor: Microsoft

Description

<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p> <p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles file operations.</p>

CWE

NVD-CWE-noinfo

Affected Products

microsoft visual studiomicrosoft visual studio 2017microsoft visual studio 2019microsoft windows 10microsoft windows server 2016microsoft windows server 2019

References