Microsoft Visual Studio 2017 vulnerabilities
72 known vulnerabilities affecting microsoft/visual_studio_2017.
Total CVEs
72
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH54MEDIUM17LOW1
Vulnerabilities
Page 1 of 4
CVE-2025-55240HIGHCVSS 7.3≥ 15.0, < 15.9.772025-10-14
CVE-2025-55240 [HIGH] CWE-284 CVE-2025-55240: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49739HIGHCVSS 8.8≥ 15.0, < 15.9.752025-07-08
CVE-2025-49739 [HIGH] CWE-59 CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthoriz
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2025-32703MEDIUMCVSS 5.5≥ 15.0, < 15.9.732025-05-13
CVE-2025-32703 [MEDIUM] CWE-200 CVE-2025-32703: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclos
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24998HIGHCVSS 7.3≥ 15.0, < 15.9.712025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21206HIGHCVSS 7.3≥ 15.0, < 15.9.702025-02-11
CVE-2025-21206 [HIGH] CWE-427 CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability
Visual Studio Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-21176HIGHCVSS 8.8≥ 15.0, < 15.9.692025-01-14
CVE-2025-21176 [HIGH] CWE-126 CVE-2025-21176: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-21172HIGHCVSS 7.5≥ 15.0, ≤ 15.82025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-43590HIGHCVSS 7.8≥ 15.0, < 15.9.672024-10-08
CVE-2024-43590 [HIGH] CWE-284 CVE-2024-43590: Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-43603MEDIUMCVSS 5.5≥ 15.0.0, < 15.9.672024-10-08
CVE-2024-43603 [MEDIUM] CWE-59 CVE-2024-43603: Visual Studio Collector Service Denial of Service Vulnerability
Visual Studio Collector Service Denial of Service Vulnerability
nvd
CVE-2024-29060MEDIUMCVSS 6.7≥ 15.0, < 15.9.632024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-20656HIGHCVSS 7.8≥ 15.0, < 15.9.592024-01-09
CVE-2024-20656 [HIGH] CWE-59 CVE-2024-20656: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-36897HIGHCVSS 8.1≥ 15.0, < 15.9.562023-08-08
CVE-2023-36897 [HIGH] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability
Visual Studio Tools for Office Runtime Spoofing Vulnerability
nvd
CVE-2023-24897HIGHCVSS 7.8≥ 15.0, ≤ 15.8≥ 15.9, < 15.9.552023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-33139MEDIUMCVSS 5.5≥ 15.0, < 15.8≥ 15.9, < 15.9.552023-06-14
CVE-2023-33139 [MEDIUM] CWE-125 CVE-2023-33139: Visual Studio Information Disclosure Vulnerability
Visual Studio Information Disclosure Vulnerability
nvd
CVE-2023-21808HIGHCVSS 7.8≥ 15.0, < 15.9.512023-02-14
CVE-2023-21808 [HIGH] CWE-416 CVE-2023-21808: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-21566HIGHCVSS 7.8≥ 15.0, < 15.9.522023-02-14
CVE-2023-21566 [HIGH] CWE-73 CVE-2023-21566: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2022-24767HIGHCVSS 7.8≥ 15.0, < 15.9.462022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco
GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2022-21871HIGHCVSS 7.0≥ 15.0, < 15.9.442022-01-11
CVE-2022-21871 [HIGH] CVE-2022-21871: Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
nvd
CVE-2021-42319MEDIUMCVSS 4.7≥ 15.0, ≤ 15.92021-11-10
CVE-2021-42319 [MEDIUM] CWE-269 CVE-2021-42319: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2021-42277MEDIUMCVSS 5.5≥ 15.0, ≤ 15.92021-11-10
CVE-2021-42277 [MEDIUM] CWE-269 CVE-2021-42277: Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
nvd
1 / 4Next →