CVE-2019-1486: Microsoft Visual Studio 2019
Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
Affected products
- Microsoft Visual Studio 2019: from 16.0, up to and including 16.4
- Microsoft Visual Studio Live Share: before 1.0.1374 (fixed in 1.0.1374)
Published 2019-12-10. Last modified 2026-06-17.