Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-26870

Опубликовано: 12 янв. 2021
Источник: msrc
CVSS3: 7
EPSS Низкий

Описание

Visual Studio Remote Code Execution Vulnerability

FAQ

Why is a CVE that was issued by the MITRE Corporation in the Security Update Guide?

CVE-2020-26870 documents a vulnerability in Cure53 DOMPurify which is open source software used by Visual Studio. The documented Visual Studio updates incorporate the updates in Cure53 DOMPurify which address the vulnerability.

Обновления

ПродуктСтатьяОбновление
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
Microsoft Visual Studio 2019 version 16.0
Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
Microsoft Visual Studio 2019 version 16.8

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 61%
0.00417
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

CVSS3: 6.1
nvd
больше 5 лет назад

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

CVSS3: 6.1
debian
больше 5 лет назад

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs becaus ...

CVSS3: 6.1
github
около 5 лет назад

Cross-site Scripting in dompurify

CVSS3: 6.1
fstec
больше 5 лет назад

Уязвимость библиотеки DOMPurify, связанная с непринятием мер по защите структуры веб-старницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку

EPSS

Процентиль: 61%
0.00417
Низкий

7 High

CVSS3