SB2019071515 - Information disclosure in Microsoft Visual Studio
Published: July 15, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2019-1079)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.
Remediation
Install update from vendor's website.