PT-2020-2696 · Microsoft · Windows+2

Ron Masas

·

Published

2020-05-12

·

Updated

2025-07-08

·

CVE-2020-1192

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Visual Studio Code (affected versions not specified)
Description A remote code execution issue exists when the Python extension loads workspace settings from a notebook file. This is due to insufficient input validation, which can allow an attacker to elevate their privileges. The vulnerability is part of a set of issues addressed by Microsoft patches, including over 100 vulnerabilities, 16 of which are critical. These patches affect various Microsoft products, including Office and Windows operating systems, and address issues such as privilege elevation, remote code execution, and denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-02764
CVE-2020-1192

Affected Products

Office
Visual Studio Code
Windows