Microsoft Visual Studio 2019 vulnerabilities
93 known vulnerabilities affecting microsoft/visual_studio_2019.
Total CVEs
93
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH70MEDIUM21LOW1
Vulnerabilities
Page 4 of 5
CVE-2020-1257P3HIGHCVSS 7.8≥ 16.0, ≤ 16.62020-06-09
CVE-2020-1257 [HIGH] CVE-2020-1257: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1278, CVE-2020-1293.
nvd
CVE-2020-1278P3HIGHCVSS 7.8≥ 16.0, ≤ 16.62020-06-09
CVE-2020-1278 [HIGH] CVE-2020-1278: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1293.
nvd
CVE-2019-1211P3HIGHCVSS 7.3v16.0v16.22019-08-14
CVE-2019-1211 [HIGH] CVE-2019-1211: An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses co
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user.
To exploit the vulnerability, an authenticated attacker would need to modify Git configuration files on a system prior to a full i
nvd
CVE-2025-21206P3HIGHCVSS 7.3≥ 16.0, < 16.11.442025-02-11
CVE-2025-21206 [HIGH] CWE-427 CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability
Visual Studio Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-24998P3HIGHCVSS 7.3≥ 16.0, < 16.11.452025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-25003P3HIGHCVSS 7.3≥ 16.0, < 16.11.452025-03-11
CVE-2025-25003 [HIGH] CWE-427 CVE-2025-25003: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-1723P3HIGHCVSS 7.5≥ 16.0, ≤ 16.82021-01-12
CVE-2021-1723 [HIGH] CVE-2021-1723: ASP.NET Core and Visual Studio Denial of Service Vulnerability
ASP.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2021-26423P3HIGHCVSS 7.5≥ 16.0, ≤ 16.10v8.102021-08-12
CVE-2021-26423 [HIGH] CVE-2021-26423: .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-24464P3HIGHCVSS 7.5≥ 16.0, ≤ 16.6.4≥ 16.7.0, < 16.7.26+4 more2022-03-09
CVE-2022-24464 [HIGH] CWE-400 CVE-2022-24464: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-38013P3HIGHCVSS 7.5v16.9v16.112022-09-13
CVE-2022-38013 [HIGH] CWE-400 CVE-2022-38013: .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-24767P3HIGHCVSS 7.8≥ 16.0, < 16.7.27≥ 16.8, < 16.9.19+1 more2022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco
GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2022-24512P3MEDIUMCVSS 6.3≥ 16.0, ≤ 16.6.4≥ 16.7.0, < 16.7.26+4 more2022-03-09
CVE-2022-24512 [MEDIUM] CWE-94 CVE-2022-24512: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2021-41355P4MEDIUMCVSS 5.7≥ 16.0, ≤ 16.112021-10-13
CVE-2021-41355 [MEDIUM] CVE-2021-41355: .NET Core and Visual Studio Information Disclosure Vulnerability
.NET Core and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2019-1425P3MEDIUMCVSS 6.5v16.0v16.32019-11-12
CVE-2019-1425 [MEDIUM] CWE-59 CVE-2019-1425: An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlin
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
nvd
CVE-2024-29060P4MEDIUMCVSS 6.7≥ 16.0, < 16.11.372024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2020-26870P4MEDIUMCVSS 6.1v16.0v16.4+2 more2020-10-07
CVE-2020-26870 [MEDIUM] CWE-79 CVE-2020-26870: Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
nvd
CVE-2023-36897P4MEDIUMCVSS 6.5≥ 16.0, < 16.11.292023-08-08
CVE-2023-36897 [MEDIUM] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability
Visual Studio Tools for Office Runtime Spoofing Vulnerability
nvd
CVE-2023-36759P4MEDIUMCVSS 6.7≥ 16.0, < 16.11.302023-09-12
CVE-2023-36759 [MEDIUM] CWE-822 CVE-2023-36759: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2025-32703P4MEDIUMCVSS 5.5≥ 16.0, < 16.11.472025-05-13
CVE-2025-32703 [MEDIUM] CWE-200 CVE-2025-32703: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclos
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
nvd
CVE-2021-1721P4MEDIUMCVSS 6.5≥ 16.0, ≤ 16.82021-02-25
CVE-2021-1721 [MEDIUM] CVE-2021-1721: .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
nvd