cbcvebase.

Microsoft Visual Studio 2017 vulnerabilities

73 known vulnerabilities affecting microsoft/visual_studio_2017.

Total CVEs
73
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH56MEDIUM15LOW1

Vulnerabilities

Page 1 of 4
CVE-2020-1147P1HIGHCVSS 7.8KEVPoC≥ 15.0, ≤ 15.92020-07-14
CVE-2020-1147 [HIGH] CVE-2020-1147: A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Stu A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
nvd
CVE-2018-0952P3HIGHCVSS 7.8PoCv15.82018-08-15
CVE-2018-0952 [HIGH] CVE-2018-0952: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file c An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
nvd
CVE-2019-1349P2HIGHCVSS 8.8≥ 15.0, < 15.9.182020-01-24
CVE-2019-1349 [HIGH] CWE-20 CVE-2019-1349: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
nvd
CVE-2019-1350P3HIGHCVSS 8.8≥ 15.0, < 15.9.182020-01-24
CVE-2019-1350 [HIGH] CVE-2019-1350: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
nvd
CVE-2019-1352P3HIGHCVSS 8.8≥ 15.0, < 15.9.182020-01-24
CVE-2019-1352 [HIGH] CWE-20 CVE-2019-1352: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
nvd
CVE-2019-1354P3HIGHCVSS 8.8≥ 15.0, < 15.9.182020-01-24
CVE-2019-1354 [HIGH] CWE-20 CVE-2019-1354: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.
nvd
CVE-2019-0613P3HIGHCVSS 8.8v15.92019-03-05
CVE-2019-0613 [HIGH] CWE-119 CVE-2019-0613: A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the s A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework and Visual Studio Remote Code Execution Vulnerability'.
nvd
CVE-2019-1113P3HIGHCVSS 8.8v15.9v16.0+1 more2019-07-15
CVE-2019-1113 [HIGH] CWE-20 CVE-2019-1113: A remote code execution vulnerability exists in .NET software when the software fails to check the s A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
nvd
CVE-2026-47304P3CRITICALCVSS 9.8≥ 15.0, ≤ 15.92026-07-14
CVE-2026-47304 [CRITICAL] CWE-345 CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2018-8172P3HIGHCVSS 7.8v15.7.52018-07-11
CVE-2018-8172 [HIGH] CVE-2018-8172: A remote code execution vulnerability exists in Visual Studio software when the software does not ch A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
nvd
CVE-2025-21176P3HIGHCVSS 8.8≥ 15.0, < 15.9.692025-01-14
CVE-2025-21176 [HIGH] CWE-126 CVE-2025-21176: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-49739P3HIGHCVSS 8.8≥ 15.0, < 15.9.752025-07-08
CVE-2025-49739 [HIGH] CWE-59 CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthoriz Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2020-1416P3HIGHCVSS 8.8≥ 15.0, < 15.9.252020-07-14
CVE-2020-1416 [HIGH] CWE-269 CVE-2020-1416: An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they loa An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0546P3HIGHCVSS 7.8v15.92019-01-08
CVE-2019-0546 [HIGH] CVE-2019-0546: A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handl A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio.
nvd
CVE-2025-21172P3HIGHCVSS 7.5≥ 15.0, ≤ 15.82025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2020-1597P3HIGHCVSS 7.5≥ 15.0, ≤ 15.82020-08-17
CVE-2020-1597 [HIGH] CVE-2020-1597: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attac A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by i
nvd
CVE-2019-0809P3HIGHCVSS 7.8v15.92019-04-09
CVE-2019-0809 [HIGH] CWE-426 CVE-2019-0809: A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer im A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'.
nvd
CVE-2024-20656P3HIGHCVSS 7.8≥ 15.0, < 15.9.592024-01-09
CVE-2024-20656 [HIGH] CWE-59 CVE-2024-20656: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2019-1351P3HIGHCVSS 7.5≥ 15.0, < 15.9.182020-01-24
CVE-2019-1351 [HIGH] CWE-706 CVE-2019-1351: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
nvd
CVE-2020-16856P3HIGHCVSS 7.8≥ 15.0, ≤ 15.82020-09-11
CVE-2020-16856 [HIGH] CVE-2020-16856: <p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker cou
nvd
Microsoft Visual Studio 2017 vulnerabilities | cvebase