漏洞标题
Visual Studio中Git的权限提升漏洞
漏洞描述信息
在 Git for Visual Studio improperly 解析配置文件时存在一个特权提升漏洞,也被称为 "Git for Visual Studio 特权提升漏洞"。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Git for Visual Studio Elevation of Privilege Vulnerability
漏洞描述信息
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user.
To exploit the vulnerability, an authenticated attacker would need to modify Git configuration files on a system prior to a full installation of the application. The attacker would then need to convince another user on the system to execute specific Git commands.
The update addresses the issue by changing the permissions required to edit configuration files.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Microsoft Visual Studio 权限许可和访问控制问题漏洞
漏洞描述信息
Microsoft Visual Studio是美国微软(Microsoft)公司的一款开发工具套件系列产品,也是一个基本完整的开发工具集,它包括了整个软件生命周期中所需要的大部分工具。 Microsoft Git for Visual Studio中存在提权漏洞,该漏洞源于程序没有正确地分析配置文件。攻击者可通过在完全安装完应用程序之前修改系统上的 Git 配置文件利用该漏洞在另一个本地用户的上下文中执行代码。以下产品及版本受到影响:Microsoft Visual Studio 2017,Visual
CVSS信息
N/A
漏洞类别
权限许可和访问控制问题