CVE-2020-0810: Microsoft Visual Studio 2015

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system.An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.The update addresses the vulnerability by not permitting Diagnostics Hub Standard Collector or the Visual Studio Standard Collector to create files in arbitrary locations., aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'.

Affected products

  • Microsoft Visual Studio 2015: affected versions not specified
  • Microsoft Visual Studio 2017: from 15.1, up to and including 15.9
  • Microsoft Visual Studio 2019: from 16.0, up to and including 16.4
  • Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
  • Microsoft Windows Server 2016: affected versions not specified; version 1803 only; version 1903 only; version 1909 only
  • Microsoft Windows Server 2019: affected versions not specified

Published 2020-03-12. Last modified 2026-06-17.