Security Updates for Microsoft Visual Studio Products (February 2019)

high Nessus Plugin ID 122133

Synopsis

The Microsoft Visual Studio Products are missing a security update.

Description

The Microsoft Visual Studio Products are missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Visual Studio software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2019-0613)

- A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's. An attacker who successfully exploited this vulnerability could use it to bypass security logic intended to ensure that a user-provided URL belonged to a specific hostname or a subdomain of that hostname. This could be used to cause privileged communication to be made to an untrusted service as if it was a trusted service. To exploit the vulnerability, an attacker must provide a URL string to an application that attempts to verify that the URL belongs to a specific hostname or to a subdomain of that hostname. The application must then make an HTTP request to the attacker-provided URL either directly or by sending a processed version of the attacker-provided URL to a web browser.
(CVE-2019-0657)

Solution

Microsoft has released the following security updates to address this issue:
- Update 15.0 (26228.73) for Visual Studio 2017
- Update 15.9.7 for Visual Studio 2017 15.9

See Also

http://www.nessus.org/u?30855885

http://www.nessus.org/u?1d93e731

Plugin Details

Severity: High

ID: 122133

File Name: smb_nt_ms19_feb_visual_studio.nasl

Version: 1.5

Type: local

Agent: windows

Published: 2/12/2019

Updated: 6/27/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2019-0613

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:visual_studio

Required KB Items: SMB/MS_Bulletin_Checks/Possible, installed_sw/Microsoft Visual Studio

Exploit Ease: No known exploits are available

Patch Publication Date: 2/12/2019

Vulnerability Publication Date: 2/12/2019

Reference Information

CVE: CVE-2019-0613, CVE-2019-0657

BID: 106872, 106890