Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability
Released: Jun 9, 2020
- Assigning CNA
- Microsoft
- CVE.org link
- CVE-2020-1202
Executive Summary
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses the vulnerability by correcting how the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector handle objects in memory.
Exploitability
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
- Publicly disclosed
- No
- Exploited
- No
- Exploitability assessment
- Exploitation Less Likely
Acknowledgements
- Yuki Chen of Qihoo 360 Vulcan Team working with 360 BugCloud
Security Updates
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle.
Disclaimer
Revisions
Information published.