Description
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p> <p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles data operations.</p>
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
E
Physical
RL
O
RC
Changed
Affected products
- microsoft / visual_studio2015 – 2015
- microsoft / visual_studio_2017
- microsoft / visual_studio_2019
- microsoft / Windows 101903 – 1903
- microsoft / Windows 101709 – 1709
- microsoft / windows_10_1507
- microsoft / windows_10_1507
- microsoft / windows_10_1607
- microsoft / windows_10_1607
- microsoft / windows_10_1803
- microsoft / windows_10_1803
- microsoft / windows_10_1809
- microsoft / windows_10_1809
- microsoft / windows_10_1809
- microsoft / windows_10_1909
- microsoft / windows_10_1909
- microsoft / windows_server_1903
- microsoft / windows_server_1909
- microsoft / windows_server_2004
- microsoft / Windows Server 2016
- microsoft / Windows Server 2019
References
Updated 26m ago · 8 sources