CVE-2020-1393: Microsoft Visual Studio
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.
Affected products
- Microsoft Visual Studio: version 2015 only
- Microsoft Visual Studio 2017: from 15.0, before 15.9.25 (fixed in 15.9.25)
- Microsoft Visual Studio 2019: from 16.0, before 16.4.11 (fixed in 16.4.11); from 16.5.0, before 16.6.4 (fixed in 16.6.4)
- Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
- Microsoft Windows Server 2016: affected versions not specified; version 1903 only; version 1909 only; version 2004 only
- Microsoft Windows Server 2019: affected versions not specified
Published 2020-07-14. Last modified 2026-06-17.