Microsoft Visual Studio 2022 vulnerabilities
108 known vulnerabilities affecting microsoft/visual_studio_2022.
Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH81MEDIUM21
Vulnerabilities
Page 3 of 6
CVE-2026-50646P3HIGHCVSS 7.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32177P3HIGHCVSS 7.3≥ 17.12.0, < 17.12.20≥ 17.14.0, < 17.14.322026-05-12
CVE-2026-32177 [HIGH] CWE-20 CVE-2026-32177: Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-26682P3HIGHCVSS 7.5≥ 17.8.0, < 17.8.20≥ 17.10.0, < 17.10.13+2 more2025-04-08
CVE-2025-26682 [HIGH] CWE-770 CVE-2025-26682: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-32702P3HIGHCVSS 7.8≥ 17.8.0, < 17.8.21≥ 17.10.0, < 17.10.14+2 more2025-05-13
CVE-2025-32702 [HIGH] CWE-77 CVE-2025-32702: Improper neutralization of special elements used in a command ('command injection') in Visual Studio
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-30399P3HIGHCVSS 7.5≥ 17.8.0, < 17.8.22≥ 17.10.0, < 17.10.16+2 more2025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-47305P3HIGHCVSS 7.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-47305 [HIGH] CWE-693 CVE-2026-47305: Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locall
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-35390P3HIGHCVSS 7.8≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-35390 [HIGH] CWE-77 CVE-2023-35390: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-24070P3HIGHCVSS 7.0≥ 17.8.0, < 17.8.19≥ 17.10.0, < 17.10.12+2 more2025-03-11
CVE-2025-24070 [HIGH] CWE-1390 CVE-2025-24070: Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate p
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2023-28260P3HIGHCVSS 7.8≥ 17.0, < 17.0.21≥ 17.2, < 17.2.15+2 more2023-04-11
CVE-2023-28260 [HIGH] CVE-2023-28260: .NET DLL Hijacking Remote Code Execution Vulnerability
.NET DLL Hijacking Remote Code Execution Vulnerability
nvd
CVE-2024-21409P3HIGHCVSS 7.3≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-55240P3HIGHCVSS 7.3≥ 17.10.0, < 17.10.20≥ 17.12.0, < 17.12.13+1 more2025-10-14
CVE-2025-55240 [HIGH] CWE-284 CVE-2025-55240: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35391P3HIGHCVSS 7.5≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-35391 [HIGH] CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2024-43590P3HIGHCVSS 7.8≥ 17.6.0, < 17.6.20≥ 17.8.0, < 17.8.15+2 more2024-10-08
CVE-2024-43590 [HIGH] CWE-284 CVE-2024-43590: Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-29804P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.20≥ 17.10.0, < 17.10.13+2 more2025-04-08
CVE-2025-29804 [HIGH] CWE-284 CVE-2025-29804: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5≥ 17.0, ≤ 17.0.7v17.12020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2025-29802P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.20≥ 17.10.0, < 17.10.13+1 more2025-04-08
CVE-2025-29802 [HIGH] CWE-427 CVE-2025-29802: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50659 [MEDIUM] CWE-116 CVE-2026-50659: Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2023-24897P3HIGHCVSS 7.8≥ 17.0, < 17.0.22≥ 17.2, < 17.2.16+2 more2023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd