Microsoft Visual Studio 2022 vulnerabilities
108 known vulnerabilities affecting microsoft/visual_studio_2022.
Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH81MEDIUM21
Vulnerabilities
Page 5 of 6
CVE-2025-24998P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.19≥ 17.10.0, < 17.10.12+2 more2025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-25003P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.19≥ 17.10.0, < 17.10.12+2 more2025-03-11
CVE-2025-25003 [HIGH] CWE-427 CVE-2025-25003: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30045P3MEDIUMCVSS 6.3≥ 17.4.0, < 17.4.19≥ 17.6.0, < 17.6.15+2 more2024-05-14
CVE-2024-30045 [MEDIUM] CWE-122 CVE-2024-30045: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-38095P3HIGHCVSS 7.5≥ 17.4.0, < 17.4.21≥ 17.6.0, < 17.6.17+2 more2024-07-09
CVE-2024-38095 [HIGH] CWE-20 CVE-2024-38095: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-43499P3HIGHCVSS 7.5≥ 17.6, < 17.6.21≥ 17.8, < 17.8.16+2 more2024-11-12
CVE-2024-43499 [HIGH] CWE-409 CVE-2024-43499: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-38081P3HIGHCVSS 7.3≥ 17.4, < 17.4.21≥ 17.6, < 17.6.17+1 more2024-07-09
CVE-2024-38081 [HIGH] CWE-59 CVE-2024-38081: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-33135P3HIGHCVSS 7.3≥ 17.0, < 17.0.22≥ 17.2, < 17.2.16+2 more2023-06-14
CVE-2023-33135 [HIGH] CVE-2023-33135: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2022-24464P3HIGHCVSS 7.5≥ 17.0, < 17.0.72022-03-09
CVE-2022-24464 [HIGH] CWE-400 CVE-2022-24464: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-38013P3HIGHCVSS 7.5v17.0v17.2+1 more2022-09-13
CVE-2022-38013 [HIGH] CWE-400 CVE-2022-38013: .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-38178P3HIGHCVSS 7.5≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.102023-08-08
CVE-2023-38178 [HIGH] CWE-400 CVE-2023-38178: .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-24767P3HIGHCVSS 7.8≥ 17.0, < 17.0.8≥ 17.1.0, < 17.1.42022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco
GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2022-24512P3MEDIUMCVSS 6.3≥ 17.0, < 17.0.72022-03-09
CVE-2022-24512 [MEDIUM] CWE-94 CVE-2022-24512: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-49044P4MEDIUMCVSS 6.7≥ 17.6.0, < 17.6.21≥ 17.8.0, < 17.8.16+2 more2024-11-12
CVE-2024-49044 [MEDIUM] CWE-284 CVE-2024-49044: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-29060P4MEDIUMCVSS 6.7≥ 17.4, < 17.4.20≥ 17.6, < 17.6.16+2 more2024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2025-55248P4MEDIUMCVSS 5.7≥ 17.10.0, < 17.10.20≥ 17.12.0, < 17.12.13+1 more2025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
nvd
CVE-2024-38167P4MEDIUMCVSS 6.5≥ 17.6.0, < 17.6.18≥ 17.8.0, < 17.8.13+1 more2024-08-13
CVE-2024-38167 [MEDIUM] CWE-319 CVE-2024-38167: .NET and Visual Studio Information Disclosure Vulnerability
.NET and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2023-36799P4MEDIUMCVSS 6.5≥ 17.2, < 17.2.19≥ 17.4, < 17.4.11+2 more2023-09-12
CVE-2023-36799 [MEDIUM] CWE-400 CVE-2023-36799: .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-36897P4MEDIUMCVSS 6.5≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-36897 [MEDIUM] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability
Visual Studio Tools for Office Runtime Spoofing Vulnerability
nvd
CVE-2023-32032P4MEDIUMCVSS 6.5≥ 17.0, < 17.0.22≥ 17.2, < 17.2.16+2 more2023-06-14
CVE-2023-32032 [MEDIUM] CWE-20 CVE-2023-32032: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-21319P4MEDIUMCVSS 6.8≥ 17.2.0, < 17.2.23≥ 17.4.0, < 17.4.15+2 more2024-01-09
CVE-2024-21319 [MEDIUM] CWE-20 CVE-2024-21319: Microsoft Identity Denial of service vulnerability
Microsoft Identity Denial of service vulnerability
nvd