cbcvebase.

Microsoft Visual Studio 2017 vulnerabilities

73 known vulnerabilities affecting microsoft/visual_studio_2017.

Total CVEs
73
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH56MEDIUM15LOW1

Vulnerabilities

Page 3 of 4
CVE-2021-42277P3HIGHCVSS 7.8≥ 15.0, ≤ 15.92021-11-10
CVE-2021-42277 [HIGH] CWE-269 CVE-2021-42277: Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
nvd
CVE-2020-0793P3HIGHCVSS 7.8≥ 15.1, ≤ 15.92020-03-12
CVE-2020-0793 [HIGH] CVE-2020-0793: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1130P3HIGHCVSS 7.8≥ 15.0, < 15.9.272020-09-11
CVE-2020-1130 [HIGH] CVE-2020-1130: <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improp An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the
nvd
CVE-2021-1680P3HIGHCVSS 7.8≥ 15.0, ≤ 15.82021-01-12
CVE-2021-1680 [HIGH] CWE-269 CVE-2021-1680: Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
nvd
CVE-2022-21871P3HIGHCVSS 7.8≥ 15.0, < 15.9.442022-01-11
CVE-2022-21871 [HIGH] CVE-2022-21871: Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
nvd
CVE-2020-1393P3HIGHCVSS 7.8≥ 15.0, < 15.9.252020-07-14
CVE-2020-1393 [HIGH] CVE-2020-1393: An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector S An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.
nvd
CVE-2020-1203P3HIGHCVSS 7.8≥ 15.0, ≤ 15.92020-06-09
CVE-2020-1203 [HIGH] CVE-2020-1203: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Vi An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1202.
nvd
CVE-2020-1202P3HIGHCVSS 7.8≥ 15.0, ≤ 15.92020-06-09
CVE-2020-1202 [HIGH] CVE-2020-1202: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Vi An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1203.
nvd
CVE-2020-1293P3HIGHCVSS 7.8≥ 15.0, ≤ 15.92020-06-09
CVE-2020-1293 [HIGH] CVE-2020-1293: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1278.
nvd
CVE-2020-1257P3HIGHCVSS 7.8≥ 15.0, ≤ 15.92020-06-09
CVE-2020-1257 [HIGH] CVE-2020-1257: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1278, CVE-2020-1293.
nvd
CVE-2020-1278P3HIGHCVSS 7.8≥ 15.0, ≤ 15.92020-06-09
CVE-2020-1278 [HIGH] CVE-2020-1278: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1293.
nvd
CVE-2019-1211P3HIGHCVSS 7.3v15.92019-08-14
CVE-2019-1211 [HIGH] CVE-2019-1211: An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses co An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerability, an authenticated attacker would need to modify Git configuration files on a system prior to a full i
nvd
CVE-2025-21206P3HIGHCVSS 7.3≥ 15.0, < 15.9.702025-02-11
CVE-2025-21206 [HIGH] CWE-427 CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability Visual Studio Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-24998P3HIGHCVSS 7.3≥ 15.0, < 15.9.712025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2018-8232P3HIGHCVSS 7.8v15.7.5v15.82018-07-11
CVE-2018-8232 [HIGH] CWE-20 CVE-2018-8232: A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Micr A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tampering Vulnerability." This affects Microsoft Visual Studio.
nvd
CVE-2021-26423P3HIGHCVSS 7.5≥ 15.0, ≤ 15.92021-08-12
CVE-2021-26423 [HIGH] CVE-2021-26423: .NET Core and Visual Studio Denial of Service Vulnerability .NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-24767P3HIGHCVSS 7.8≥ 15.0, < 15.9.462022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2019-1425P3MEDIUMCVSS 6.5v15.92019-11-12
CVE-2019-1425 [MEDIUM] CWE-59 CVE-2019-1425: An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlin An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
nvd
CVE-2024-29060P4MEDIUMCVSS 6.7≥ 15.0, < 15.9.632024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2019-0657P4MEDIUMCVSS 5.9v15.92019-03-05
CVE-2019-0657 [MEDIUM] CWE-20 CVE-2019-0657: A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
nvd
Microsoft Visual Studio 2017 vulnerabilities | cvebase