Visual Studio 2017
by Microsoft
CVEs (62)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1108 | Hig | 0.50 | 7.5 | 0.12 | May 21, 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. | ||
| CVE-2021-26423 | Hig | 0.49 | 7.5 | 0.04 | Aug 12, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1597 | Hig | 0.49 | 7.5 | 0.07 | Aug 17, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without… | ||
| CVE-2019-1351 | Hig | 0.49 | 7.5 | 0.09 | Jan 24, 2020 | A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'. | ||
| CVE-2025-55240 | Hig | 0.47 | 7.3 | 0.00 | Oct 14, 2025 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2021-1639 | Hig | 0.46 | 7.0 | 0.02 | Feb 25, 2021 | Visual Studio Code Remote Code Execution Vulnerability | ||
| CVE-2024-29060 | Med | 0.44 | 6.7 | 0.01 | Jun 11, 2024 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2021-1721 | Med | 0.43 | 6.5 | 0.03 | Feb 25, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1130 | Med | 0.43 | 6.6 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this… | ||
| CVE-2019-1425 | Med | 0.42 | 6.5 | 0.03 | Nov 12, 2019 | An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0757 | Med | 0.42 | 6.5 | 0.03 | Apr 9, 2019 | A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'. | ||
| CVE-2019-0657 | Med | 0.39 | 5.9 | 0.05 | Mar 5, 2019 | A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. | ||
| CVE-2025-32703 | Med | 0.36 | 5.5 | 0.00 | May 13, 2025 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | ||
| CVE-2024-43603 | Med | 0.36 | 5.5 | 0.01 | Oct 8, 2024 | Visual Studio Collector Service Denial of Service Vulnerability | ||
| CVE-2023-33139 | Med | 0.36 | 5.5 | 0.01 | Jun 14, 2023 | Visual Studio Information Disclosure Vulnerability | ||
| CVE-2020-17100 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2020 | Visual Studio Tampering Vulnerability | ||
| CVE-2020-1133 | Med | 0.36 | 5.5 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this… | ||
| CVE-2020-0899 | Med | 0.36 | 5.5 | 0.01 | Apr 15, 2020 | An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'. | ||
| CVE-2021-34485 | Med | 0.33 | 5.0 | 0.01 | Aug 12, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2020-26870 | Med | 0.33 | 6.1 | 0.05 | Oct 7, 2020 | Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements. |
- risk 0.50cvss 7.5epss 0.12
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.04
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.07
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without…
- risk 0.49cvss 7.5epss 0.09
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
- risk 0.47cvss 7.3epss 0.00
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.02
Visual Studio Code Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.43cvss 6.5epss 0.03
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.43cvss 6.6epss 0.01
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this…
- risk 0.42cvss 6.5epss 0.03
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
- risk 0.42cvss 6.5epss 0.03
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
- risk 0.39cvss 5.9epss 0.05
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
- risk 0.36cvss 5.5epss 0.00
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Visual Studio Collector Service Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
Visual Studio Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Visual Studio Tampering Vulnerability
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this…
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'.
- risk 0.33cvss 5.0epss 0.01
.NET Core and Visual Studio Information Disclosure Vulnerability
- risk 0.33cvss 6.1epss 0.05
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Page 3 of 4