Microsoft Visual Studio 2022 Version 17.8 vulnerabilities

62 known vulnerabilities affecting microsoft/microsoft_visual_studio_2022_version_17.8.

Total CVEs
62
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH51MEDIUM9

Vulnerabilities

Page 1 of 4
CVE-2025-49739HIGHCVSS 8.8≥ 17.8.0, < 17.8.232025-07-08
CVE-2025-49739 [HIGH] CWE-59 CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthoriz Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2025-30399HIGHCVSS 7.5≥ 17.8.0, < 17.8.222025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-47959HIGHCVSS 7.1≥ 17.8.0, < 17.8.222025-06-13
CVE-2025-47959 [HIGH] CWE-77 CVE-2025-47959: Improper neutralization of special elements used in a command ('command injection') in Visual Studio Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-32702HIGHCVSS 7.8≥ 17.8.0, < 17.8.212025-05-13
CVE-2025-32702 [HIGH] CWE-77 CVE-2025-32702: Improper neutralization of special elements used in a command ('command injection') in Visual Studio Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
cvelistv5nvd
CVE-2025-26646HIGHCVSS 8.0≥ 17.8.0, < 17.8.212025-05-13
CVE-2025-26646 [HIGH] CWE-73 CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allo External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2025-32703MEDIUMCVSS 5.5≥ 17.8.0, < 17.8.212025-05-13
CVE-2025-32703 [MEDIUM] CWE-200 CVE-2025-32703: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclos Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2025-29804HIGHCVSS 7.3≥ 17.8.0, < 17.8.202025-04-08
CVE-2025-29804 [HIGH] CWE-284 CVE-2025-29804: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-26682HIGHCVSS 7.5≥ 17.8.0, < 17.8.202025-04-08
CVE-2025-26682 [HIGH] CWE-770 CVE-2025-26682: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2025-29802HIGHCVSS 7.3≥ 17.8.0, < 17.8.202025-04-08
CVE-2025-29802 [HIGH] CWE-427 CVE-2025-29802: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-24070HIGHCVSS 7.0≥ 17.8.0, < 17.8.192025-03-11
CVE-2025-24070 [HIGH] CWE-1390 CVE-2025-24070: Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate p Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2025-24998HIGHCVSS 7.3≥ 17.8.0, < 17.8.192025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-25003HIGHCVSS 7.3≥ 17.8.0, < 17.8.192025-03-11
CVE-2025-25003 [HIGH] CWE-427 CVE-2025-25003: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-21206HIGHCVSS 7.3≥ 17.8.0, < 17.8.182025-02-11
CVE-2025-21206 [HIGH] CWE-427 CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability Visual Studio Installer Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2025-21176HIGHCVSS 8.8≥ 17.8.0, < 17.8.172025-01-14
CVE-2025-21176 [HIGH] CWE-126 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21173HIGHCVSS 7.3≥ 17.8.0, < 17.8.172025-01-14
CVE-2025-21173 [HIGH] CWE-379 .NET Elevation of Privilege Vulnerability .NET Elevation of Privilege Vulnerability .NET Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-21178HIGHCVSS 8.8≥ 17.8.0, < 17.8.172025-01-14
CVE-2025-21178 [HIGH] CWE-122 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21171HIGHCVSS 7.5≥ 17.8.0, < 17.8.172025-01-14
CVE-2025-21171 [HIGH] CWE-122 .NET Remote Code Execution Vulnerability .NET Remote Code Execution Vulnerability .NET Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21172HIGHCVSS 7.5≥ 17.8.0, < 17.8.172025-01-14
CVE-2025-21172 [HIGH] CWE-190 .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2024-43498CRITICALCVSS 9.8≥ 17.8.0, < 17.8.162024-11-12
CVE-2024-43498 [CRITICAL] CWE-843 CVE-2024-43498: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2024-43499HIGHCVSS 7.5≥ 17.8.0, < 17.8.162024-11-12
CVE-2024-43499 [HIGH] CWE-409 CVE-2024-43499: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
cvelistv5nvd