Microsoft Visual Studio 2017 Version 15.9 vulnerabilities

80 known vulnerabilities affecting microsoft/microsoft_visual_studio_2017_version_15.9.

Total CVEs
80
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH65MEDIUM14LOW1

Vulnerabilities

Page 1 of 4
CVE-2025-55240HIGHCVSS 7.3≥ 15.9.0, < 15.9.772025-10-14
CVE-2025-55240 [HIGH] CWE-284 CVE-2025-55240: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49739HIGHCVSS 8.8≥ 15.9.0, < 15.9.752025-07-08
CVE-2025-49739 [HIGH] CWE-59 CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthoriz Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2025-32703MEDIUMCVSS 5.5≥ 15.9.0, < 15.9.732025-05-13
CVE-2025-32703 [MEDIUM] CWE-200 CVE-2025-32703: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclos Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2025-24998HIGHCVSS 7.3≥ 15.9.0, < 15.9.712025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-21206HIGHCVSS 7.3≥ 15.9.0, < 15.9.702025-02-11
CVE-2025-21206 [HIGH] CWE-427 CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability Visual Studio Installer Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2025-21176HIGHCVSS 8.8≥ 15.9.0, < 15.9.692025-01-14
CVE-2025-21176 [HIGH] CWE-126 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21178HIGHCVSS 8.8≥ 15.9.0, < 15.9.692025-01-14
CVE-2025-21178 [HIGH] CWE-122 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21172HIGHCVSS 7.5≥ 15.9.0, < 15.9.692025-01-14
CVE-2025-21172 [HIGH] CWE-190 .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2024-43590HIGHCVSS 7.8≥ 15.9.0, < 15.9.672024-10-08
CVE-2024-43590 [HIGH] CWE-284 CVE-2024-43590: Visual C++ Redistributable Installer Elevation of Privilege Vulnerability Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2024-43603MEDIUMCVSS 5.5≥ 15.9.0, < 15.9.672024-10-08
CVE-2024-43603 [MEDIUM] CWE-59 CVE-2024-43603: Visual Studio Collector Service Denial of Service Vulnerability Visual Studio Collector Service Denial of Service Vulnerability
cvelistv5nvd
CVE-2024-35272HIGHCVSS 8.8≥ 15.9.0, < 15.9.662024-07-09
CVE-2024-35272 [HIGH] CWE-122 CVE-2024-35272: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2024-30052MEDIUMCVSS 4.7≥ 15.9.0, < 15.9.632024-06-11
CVE-2024-30052 [MEDIUM] CWE-693 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2024-29060MEDIUMCVSS 6.7≥ 15.9.0, < 15.9.632024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2024-20656HIGHCVSS 7.8≥ 15.9.0, < 15.9.592024-01-09
CVE-2024-20656 [HIGH] CWE-59 CVE-2024-20656: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2023-36796HIGHCVSS 7.8≥ 15.9.0, < 15.9.572023-09-12
CVE-2023-36796 [HIGH] CWE-191 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36792HIGHCVSS 7.8≥ 15.9.0, < 15.9.572023-09-12
CVE-2023-36792 [HIGH] CWE-190 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36793HIGHCVSS 7.8≥ 15.9.0, < 15.9.572023-09-12
CVE-2023-36793 [HIGH] CWE-122 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36794HIGHCVSS 7.8≥ 15.9.0, < 15.9.572023-09-12
CVE-2023-36794 [HIGH] CWE-191 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36897MEDIUMCVSS 6.5≥ 15.9.0, < 15.9.562023-08-08
CVE-2023-36897 [MEDIUM] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability Visual Studio Tools for Office Runtime Spoofing Vulnerability
cvelistv5nvd
CVE-2023-24897HIGHCVSS 7.8≥ 15.9.0, < 15.9.552023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd