Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability

According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?

An authorized attacker could create a malicious extension and then wait for an authenticated user to create a new Visual Studio project that uses that extension. The result is that the attacker could gain the privileges of the user.

Microsoft Security Response Center
#vulnerability#auth#Visual Studio#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-38016: Microsoft Office Visio Remote Code Execution Vulnerability