Vulnerability Description
A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Application Inspector | <= 1.0.23 |
Related Weaknesses (CWE)
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0872PatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0872PatchVendor Advisory
FAQ
What is CVE-2020-0872?
CVE-2020-0872 is a vulnerability with a CVSS score of 9.6 (CRITICAL). A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'R...
How severe is CVE-2020-0872?
CVE-2020-0872 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-0872?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Application Inspector.