PT-2019-1540 · Microsoft+1 · .Net Framework+4

Jonathan Birch

·

Published

2019-02-12

·

Updated

2022-05-14

·

CVE-2019-0657

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Visual Studio versions (affected versions not specified) Microsoft .NET Framework versions (affected versions not specified) Microsoft .NET Core versions (affected versions not specified) Microsoft PowerShell versions (affected versions not specified)
Description The issue is related to errors in the representation of information by the user interface, allowing a remote attacker to conduct spoofing attacks. It is also associated with the way certain .Net Framework API's and Visual Studio parse URL's, enabling attackers to bypass security logic that checks the ownership of user-provided URLs to specific nodes or subdomains, and establish a privileged connection to an untrusted service as if it were trusted.
Recommendations For Microsoft Visual Studio, update to a version that includes a fix for this issue. For Microsoft .NET Framework, update to a version that includes a fix for this issue. For Microsoft .NET Core, update to a version that includes a fix for this issue. For Microsoft PowerShell, update to a version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

UI Misrepresentation of Critical Information

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1418
BDU:2019-01039
CVE-2019-0657
GHSA-X5QJ-9VMX-7G6G
RHSA-2019:0349

Affected Products

.Net Framework
Alt Linux
Net Core
Powershell
Visual Studio