Microsoft Visual Studio 2022 vulnerabilities
108 known vulnerabilities affecting microsoft/visual_studio_2022.
Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH81MEDIUM21
Vulnerabilities
Page 2 of 6
CVE-2024-28937P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28937 [HIGH] CWE-122 CVE-2024-28937: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28938P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28938 [HIGH] CWE-125 CVE-2024-28938: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-0056P3HIGHCVSS 8.7≥ 17.2, < 17.2.23≥ 17.4, < 17.4.15+2 more2024-01-09
CVE-2024-0056 [HIGH] CWE-319 CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnera
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
nvd
CVE-2024-35264P3HIGHCVSS 8.1≥ 17.4.0, < 17.4.21≥ 17.6.0, < 17.6.17+2 more2024-07-09
CVE-2024-35264 [HIGH] CWE-416 CVE-2024-35264: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-38229P3HIGHCVSS 8.1≥ 17.6.0, < 17.6.20≥ 17.8.0, < 17.8.15+2 more2024-10-08
CVE-2024-38229 [HIGH] CWE-416 CVE-2024-38229: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-50528P3HIGHCVSS 8.2≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50528 [HIGH] CWE-302 CVE-2026-50528: Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-21257P3HIGHCVSS 8.0≥ 17.14.0, < 17.14.262026-02-10
CVE-2026-21257 [HIGH] CWE-77 CVE-2026-21257: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36758P3CRITICALCVSS 9.8≥ 17.7, ≤ 17.7.42023-09-12
CVE-2023-36758 [CRITICAL] CWE-59 CVE-2023-36758: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2026-32203P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.19≥ 17.14.0, < 17.14.302026-04-14
CVE-2026-32203 [HIGH] CWE-20 CVE-2026-32203: Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny servic
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-33170P3HIGHCVSS 8.1≥ 17.0, < 17.0.23≥ 17.2.0, < 17.2.17+2 more2023-07-11
CVE-2023-33170 [HIGH] CWE-362 CVE-2023-33170: ASP.NET and Visual Studio Security Feature Bypass Vulnerability
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2025-53773P3HIGHCVSS 7.8≥ 17.14.0, < 17.14.122025-08-12
CVE-2025-53773 [HIGH] CWE-77 CVE-2025-53773: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-47959P3HIGHCVSS 7.1≥ 17.8.0, < 17.8.22≥ 17.10.0, < 17.10.16+2 more2025-06-13
CVE-2025-47959 [HIGH] CWE-77 CVE-2025-47959: Improper neutralization of special elements used in a command ('command injection') in Visual Studio
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
nvd
CVE-2025-21172P3HIGHCVSS 7.5≥ 17.6.0, < 17.6.22≥ 17.8.0, < 17.8.17+2 more2025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-50527P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50527 [HIGH] CWE-121 CVE-2026-50527: Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50524P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50524 [HIGH] CWE-1287 CVE-2026-50524: Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-33127P3HIGHCVSS 8.1≥ 17.0, < 17.0.23≥ 17.2.0, < 17.2.17+3 more2023-07-11
CVE-2023-33127 [HIGH] CWE-1220 CVE-2023-33127: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2026-47302P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-47302 [HIGH] CWE-770 CVE-2026-47302: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50651P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50651 [HIGH] CWE-770 CVE-2026-50651: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-20656P3HIGHCVSS 7.8≥ 17.2, < 17.2.23≥ 17.4, < 17.4.15+1 more2024-01-09
CVE-2024-20656 [HIGH] CWE-59 CVE-2024-20656: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2025-26646P3HIGHCVSS 8.0≥ 17.8.0, < 17.8.21≥ 17.10.0, < 17.10.15+2 more2025-05-13
CVE-2025-26646 [HIGH] CWE-73 CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allo
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
nvd