Visual Studio 2017
by Microsoft
CVEs (93)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21172 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2021-26423 | Hig | 0.49 | 7.5 | 0.04 | Aug 12, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1597 | Hig | 0.49 | 7.5 | 0.07 | Aug 17, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without… | ||
| CVE-2020-1161 | Hig | 0.49 | 7.5 | 0.05 | May 21, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without… | ||
| CVE-2019-1351 | Hig | 0.49 | 7.5 | 0.09 | Jan 24, 2020 | A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'. | ||
| CVE-2025-21206 | Hig | 0.48 | 7.3 | 0.01 | Feb 11, 2025 | Visual Studio Installer Elevation of Privilege Vulnerability | ||
| CVE-2019-1211 | Hig | 0.48 | 7.3 | 0.02 | Aug 14, 2019 | An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerability, an authenticated… | ||
| CVE-2025-55240 | Hig | 0.47 | 7.3 | 0.00 | Oct 14, 2025 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24998 | Hig | 0.47 | 7.3 | 0.00 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2022-21871 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability | ||
| CVE-2021-1639 | Hig | 0.46 | 7.0 | 0.02 | Feb 25, 2021 | Visual Studio Code Remote Code Execution Vulnerability | ||
| CVE-2024-29060 | Med | 0.44 | 6.7 | 0.01 | Jun 11, 2024 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2021-1721 | Med | 0.43 | 6.5 | 0.03 | Feb 25, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1130 | Med | 0.43 | 6.6 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this… | ||
| CVE-2019-1425 | Med | 0.42 | 6.5 | 0.03 | Nov 12, 2019 | An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0757 | Med | 0.42 | 6.5 | 0.03 | Apr 9, 2019 | A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'. | ||
| CVE-2019-0657 | Med | 0.39 | 5.9 | 0.05 | Mar 5, 2019 | A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. | ||
| CVE-2025-32703 | Med | 0.36 | 5.5 | 0.00 | May 13, 2025 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | ||
| CVE-2024-43603 | Med | 0.36 | 5.5 | 0.01 | Oct 8, 2024 | Visual Studio Collector Service Denial of Service Vulnerability | ||
| CVE-2023-33139 | Med | 0.36 | 5.5 | 0.01 | Jun 14, 2023 | Visual Studio Information Disclosure Vulnerability |
- risk 0.49cvss 7.5epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.04
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.07
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without…
- risk 0.49cvss 7.5epss 0.05
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without…
- risk 0.49cvss 7.5epss 0.09
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
- risk 0.48cvss 7.3epss 0.01
Visual Studio Installer Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.02
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerability, an authenticated…
- risk 0.47cvss 7.3epss 0.00
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.02
Visual Studio Code Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.43cvss 6.5epss 0.03
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.43cvss 6.6epss 0.01
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this…
- risk 0.42cvss 6.5epss 0.03
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
- risk 0.42cvss 6.5epss 0.03
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
- risk 0.39cvss 5.9epss 0.05
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
- risk 0.36cvss 5.5epss 0.00
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Visual Studio Collector Service Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
Visual Studio Information Disclosure Vulnerability
Page 4 of 5