Visual Studio
by Microsoft
CVEs (278)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21409 | Hig | 0.48 | 7.3 | 0.03 | Apr 9, 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-33135 | Hig | 0.48 | 7.3 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2023-33128 | Hig | 0.48 | 7.3 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-33126 | Hig | 0.48 | 7.3 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2022-41042 | Hig | 0.48 | 7.4 | 0.02 | Oct 11, 2022 | Visual Studio Code Information Disclosure Vulnerability | ||
| CVE-2022-38020 | Hig | 0.48 | 7.3 | 0.01 | Sep 13, 2022 | Visual Studio Code Elevation of Privilege Vulnerability | ||
| CVE-2021-31204 | Hig | 0.48 | 7.3 | 0.01 | May 11, 2021 | .NET and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2019-1211 | Hig | 0.48 | 7.3 | 0.02 | Aug 14, 2019 | An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerability, an authenticated… | ||
| CVE-2026-32177 | Hig | 0.47 | 7.3 | 0.01 | May 12, 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-55240 | Hig | 0.47 | 7.3 | 0.00 | Oct 14, 2025 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-47959 | Hig | 0.47 | 7.1 | 0.07 | Jun 13, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network. | ||
| CVE-2025-26631 | Hig | 0.47 | 7.3 | 0.01 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-25003 | Hig | 0.47 | 7.3 | 0.00 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24998 | Hig | 0.47 | 7.3 | 0.00 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21405 | Hig | 0.47 | 7.3 | 0.01 | Jan 14, 2025 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2023-38171 | Hig | 0.47 | 7.5 | 0.69 | Oct 10, 2023 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2022-26921 | Hig | 0.47 | 7.3 | 0.01 | Apr 15, 2022 | Visual Studio Code Elevation of Privilege Vulnerability | ||
| CVE-2026-50526 | Hig | 0.46 | 7.0 | 0.00 | Jul 14, 2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. | ||
| CVE-2025-21264 | Hig | 0.46 | 7.1 | 0.01 | May 13, 2025 | Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-24070 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
- risk 0.48cvss 7.3epss 0.03
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
.NET and Visual Studio Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.48cvss 7.4epss 0.02
Visual Studio Code Information Disclosure Vulnerability
- risk 0.48cvss 7.3epss 0.01
Visual Studio Code Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
.NET and Visual Studio Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.02
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerability, an authenticated…
- risk 0.47cvss 7.3epss 0.01
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.1epss 0.07
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
- risk 0.47cvss 7.3epss 0.01
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.47cvss 7.5epss 0.69
Microsoft QUIC Denial of Service Vulnerability
- risk 0.47cvss 7.3epss 0.01
Visual Studio Code Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
- risk 0.46cvss 7.1epss 0.01
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- risk 0.46cvss 7.0epss 0.01
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Page 9 of 14