cbcvebase.

Microsoft Visual Studio 2022 vulnerabilities

108 known vulnerabilities affecting microsoft/visual_studio_2022.

Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH81MEDIUM21

Vulnerabilities

Page 3 of 6
CVE-2026-50646P3HIGHCVSS 7.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32177P3HIGHCVSS 7.3≥ 17.12.0, < 17.12.20≥ 17.14.0, < 17.14.322026-05-12
CVE-2026-32177 [HIGH] CWE-20 CVE-2026-32177: Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-26682P3HIGHCVSS 7.5≥ 17.8.0, < 17.8.20≥ 17.10.0, < 17.10.13+2 more2025-04-08
CVE-2025-26682 [HIGH] CWE-770 CVE-2025-26682: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-32702P3HIGHCVSS 7.8≥ 17.8.0, < 17.8.21≥ 17.10.0, < 17.10.14+2 more2025-05-13
CVE-2025-32702 [HIGH] CWE-77 CVE-2025-32702: Improper neutralization of special elements used in a command ('command injection') in Visual Studio Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-30399P3HIGHCVSS 7.5≥ 17.8.0, < 17.8.22≥ 17.10.0, < 17.10.16+2 more2025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-47305P3HIGHCVSS 7.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-47305 [HIGH] CWE-693 CVE-2026-47305: Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locall Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-35390P3HIGHCVSS 7.8≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-35390 [HIGH] CWE-77 CVE-2023-35390: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-24070P3HIGHCVSS 7.0≥ 17.8.0, < 17.8.19≥ 17.10.0, < 17.10.12+2 more2025-03-11
CVE-2025-24070 [HIGH] CWE-1390 CVE-2025-24070: Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate p Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2023-28260P3HIGHCVSS 7.8≥ 17.0, < 17.0.21≥ 17.2, < 17.2.15+2 more2023-04-11
CVE-2023-28260 [HIGH] CVE-2023-28260: .NET DLL Hijacking Remote Code Execution Vulnerability .NET DLL Hijacking Remote Code Execution Vulnerability
nvd
CVE-2024-21409P3HIGHCVSS 7.3≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-55240P3HIGHCVSS 7.3≥ 17.10.0, < 17.10.20≥ 17.12.0, < 17.12.13+1 more2025-10-14
CVE-2025-55240 [HIGH] CWE-284 CVE-2025-55240: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35391P3HIGHCVSS 7.5≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-35391 [HIGH] CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2024-43590P3HIGHCVSS 7.8≥ 17.6.0, < 17.6.20≥ 17.8.0, < 17.8.15+2 more2024-10-08
CVE-2024-43590 [HIGH] CWE-284 CVE-2024-43590: Visual C++ Redistributable Installer Elevation of Privilege Vulnerability Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-29804P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.20≥ 17.10.0, < 17.10.13+2 more2025-04-08
CVE-2025-29804 [HIGH] CWE-284 CVE-2025-29804: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5≥ 17.0, ≤ 17.0.7v17.12020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2025-29802P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.20≥ 17.10.0, < 17.10.13+1 more2025-04-08
CVE-2025-29802 [HIGH] CWE-427 CVE-2025-29802: Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-50659 [MEDIUM] CWE-116 CVE-2026-50659: Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2023-24897P3HIGHCVSS 7.8≥ 17.0, < 17.0.22≥ 17.2, < 17.2.16+2 more2023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
Microsoft Visual Studio 2022 vulnerabilities | cvebase