CVE-2020-1278
Last modified
CVE-2020-1278 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1293.. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1293.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Visual Studio | 2015 | Update3 |
| Microsoft | Visual Studio 2017 | >= 15.0, <= 15.9 | — |
| Microsoft | Visual Studio 2019 | >= 16.0, <= 16.6 | — |
| Microsoft | Windows 10 | All versions | — |
| Microsoft | Windows 10 | 1607 | — |
| Microsoft | Windows 10 | 1709 | — |
| Microsoft | Windows 10 | 1803 | — |
| Microsoft | Windows 10 | 1809 | — |
| Microsoft | Windows 10 | 1903 | — |
| Microsoft | Windows 10 | 1909 | — |
| Microsoft | Windows 10 | 2004 | — |
| Microsoft | Windows Server 2016 | All versions | — |
| Microsoft | Windows Server 2016 | 1803 | — |
| Microsoft | Windows Server 2016 | 1903 | — |
| Microsoft | Windows Server 2016 | 1909 | — |
| Microsoft | Windows Server 2016 | 2004 | — |
| Microsoft | Windows Server 2019 | All versions | — |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1278Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1278Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1278?
How severe is CVE-2020-1278?
How do I fix CVE-2020-1278?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-12774D-Link DSL-7740C does not properly validate user input, whic…6.7
- CVE-2020-12775Hicos citizen certificate client-side component does not fil…9.8
- CVE-2020-12776Openfind Mail2000 contains Broken Access Control vulnerabili…7.2
- CVE-2020-12777A function in Combodo iTop contains a vulnerability of Broke…7.5
- CVE-2020-12778Combodo iTop does not validate inputted parameters, attacker…6.1
- CVE-2020-12779Combodo iTop contains a stored Cross-site Scripting vulnerab…5.4
- CVE-2020-12780A security misconfiguration exists in Combodo iTop, which ca…7.5
- CVE-2020-12781Combodo iTop contains a cross-site request forgery (CSRF) vu…8.8
- CVE-2020-12782Openfind MailGates contains a Command Injection flaw, when r…9.8
- CVE-2020-12783Exim through 4.93 has an out-of-bounds read in the SPA authe…7.5
- CVE-2020-12784cPanel before 86.0.14 allows remote attackers to trigger a b…5.3
- CVE-2020-12785cPanel before 86.0.14 allows attackers to obtain access to t…8.1
Are you affected by CVE-2020-1278?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
