Microsoft Visual Studio 2017 vulnerabilities

72 known vulnerabilities affecting microsoft/visual_studio_2017.

Total CVEs
72
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH54MEDIUM17LOW1

Vulnerabilities

Page 1 of 4
CVE-2025-55240HIGHCVSS 7.3≥ 15.0, < 15.9.772025-10-14
CVE-2025-55240 [HIGH] CWE-284 CVE-2025-55240: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49739HIGHCVSS 8.8≥ 15.0, < 15.9.752025-07-08
CVE-2025-49739 [HIGH] CWE-59 CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthoriz Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2025-32703MEDIUMCVSS 5.5≥ 15.0, < 15.9.732025-05-13
CVE-2025-32703 [MEDIUM] CWE-200 CVE-2025-32703: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclos Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24998HIGHCVSS 7.3≥ 15.0, < 15.9.712025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21206HIGHCVSS 7.3≥ 15.0, < 15.9.702025-02-11
CVE-2025-21206 [HIGH] CWE-427 CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability Visual Studio Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-21176HIGHCVSS 8.8≥ 15.0, < 15.9.692025-01-14
CVE-2025-21176 [HIGH] CWE-126 CVE-2025-21176: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-21172HIGHCVSS 7.5≥ 15.0, ≤ 15.82025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-43590HIGHCVSS 7.8≥ 15.0, < 15.9.672024-10-08
CVE-2024-43590 [HIGH] CWE-284 CVE-2024-43590: Visual C++ Redistributable Installer Elevation of Privilege Vulnerability Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-43603MEDIUMCVSS 5.5≥ 15.0.0, < 15.9.672024-10-08
CVE-2024-43603 [MEDIUM] CWE-59 CVE-2024-43603: Visual Studio Collector Service Denial of Service Vulnerability Visual Studio Collector Service Denial of Service Vulnerability
nvd
CVE-2024-29060MEDIUMCVSS 6.7≥ 15.0, < 15.9.632024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-20656HIGHCVSS 7.8≥ 15.0, < 15.9.592024-01-09
CVE-2024-20656 [HIGH] CWE-59 CVE-2024-20656: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-36897HIGHCVSS 8.1≥ 15.0, < 15.9.562023-08-08
CVE-2023-36897 [HIGH] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability Visual Studio Tools for Office Runtime Spoofing Vulnerability
nvd
CVE-2023-24897HIGHCVSS 7.8≥ 15.0, ≤ 15.8≥ 15.9, < 15.9.552023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-33139MEDIUMCVSS 5.5≥ 15.0, < 15.8≥ 15.9, < 15.9.552023-06-14
CVE-2023-33139 [MEDIUM] CWE-125 CVE-2023-33139: Visual Studio Information Disclosure Vulnerability Visual Studio Information Disclosure Vulnerability
nvd
CVE-2023-21808HIGHCVSS 7.8≥ 15.0, < 15.9.512023-02-14
CVE-2023-21808 [HIGH] CWE-416 CVE-2023-21808: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-21566HIGHCVSS 7.8≥ 15.0, < 15.9.522023-02-14
CVE-2023-21566 [HIGH] CWE-73 CVE-2023-21566: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2022-24767HIGHCVSS 7.8≥ 15.0, < 15.9.462022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2022-21871HIGHCVSS 7.0≥ 15.0, < 15.9.442022-01-11
CVE-2022-21871 [HIGH] CVE-2022-21871: Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
nvd
CVE-2021-42319MEDIUMCVSS 4.7≥ 15.0, ≤ 15.92021-11-10
CVE-2021-42319 [MEDIUM] CWE-269 CVE-2021-42319: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2021-42277MEDIUMCVSS 5.5≥ 15.0, ≤ 15.92021-11-10
CVE-2021-42277 [MEDIUM] CWE-269 CVE-2021-42277: Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
nvd
Microsoft Visual Studio 2017 vulnerabilities | cvebase