CVE-2020-0872: Microsoft Application Inspector

Critical severity, CVSS 9.6. EPSS: 10.1% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.

Affected products

  • Microsoft Application Inspector: up to and including 1.0.23

Published 2020-03-12. Last modified 2026-06-17.