CVE-2019-1351
CVE-2019-1351
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 8.7%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
24 Jan 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
Affected products
Microsoft · Microsoft Visual Studio 2017Microsoft · Microsoft Visual Studio 2017 version 15.9 (includes 15.1 - 15.8)Microsoft · Microsoft Visual Studio 2019Microsoft · Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)References
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1351https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30