cbcvebase.

Microsoft Visual Studio 2022 vulnerabilities

108 known vulnerabilities affecting microsoft/visual_studio_2022.

Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH81MEDIUM21

Vulnerabilities

Page 5 of 6
CVE-2025-24998P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.19≥ 17.10.0, < 17.10.12+2 more2025-03-11
CVE-2025-24998 [HIGH] CWE-427 CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-25003P3HIGHCVSS 7.3≥ 17.8.0, < 17.8.19≥ 17.10.0, < 17.10.12+2 more2025-03-11
CVE-2025-25003 [HIGH] CWE-427 CVE-2025-25003: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privilege Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30045P3MEDIUMCVSS 6.3≥ 17.4.0, < 17.4.19≥ 17.6.0, < 17.6.15+2 more2024-05-14
CVE-2024-30045 [MEDIUM] CWE-122 CVE-2024-30045: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-38095P3HIGHCVSS 7.5≥ 17.4.0, < 17.4.21≥ 17.6.0, < 17.6.17+2 more2024-07-09
CVE-2024-38095 [HIGH] CWE-20 CVE-2024-38095: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-43499P3HIGHCVSS 7.5≥ 17.6, < 17.6.21≥ 17.8, < 17.8.16+2 more2024-11-12
CVE-2024-43499 [HIGH] CWE-409 CVE-2024-43499: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-38081P3HIGHCVSS 7.3≥ 17.4, < 17.4.21≥ 17.6, < 17.6.17+1 more2024-07-09
CVE-2024-38081 [HIGH] CWE-59 CVE-2024-38081: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-33135P3HIGHCVSS 7.3≥ 17.0, < 17.0.22≥ 17.2, < 17.2.16+2 more2023-06-14
CVE-2023-33135 [HIGH] CVE-2023-33135: .NET and Visual Studio Elevation of Privilege Vulnerability .NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2022-24464P3HIGHCVSS 7.5≥ 17.0, < 17.0.72022-03-09
CVE-2022-24464 [HIGH] CWE-400 CVE-2022-24464: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-38013P3HIGHCVSS 7.5v17.0v17.2+1 more2022-09-13
CVE-2022-38013 [HIGH] CWE-400 CVE-2022-38013: .NET Core and Visual Studio Denial of Service Vulnerability .NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-38178P3HIGHCVSS 7.5≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.102023-08-08
CVE-2023-38178 [HIGH] CWE-400 CVE-2023-38178: .NET Core and Visual Studio Denial of Service Vulnerability .NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-24767P3HIGHCVSS 7.8≥ 17.0, < 17.0.8≥ 17.1.0, < 17.1.42022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2022-24512P3MEDIUMCVSS 6.3≥ 17.0, < 17.0.72022-03-09
CVE-2022-24512 [MEDIUM] CWE-94 CVE-2022-24512: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-49044P4MEDIUMCVSS 6.7≥ 17.6.0, < 17.6.21≥ 17.8.0, < 17.8.16+2 more2024-11-12
CVE-2024-49044 [MEDIUM] CWE-284 CVE-2024-49044: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-29060P4MEDIUMCVSS 6.7≥ 17.4, < 17.4.20≥ 17.6, < 17.6.16+2 more2024-06-11
CVE-2024-29060 [MEDIUM] CWE-284 CVE-2024-29060: Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2025-55248P4MEDIUMCVSS 5.7≥ 17.10.0, < 17.10.20≥ 17.12.0, < 17.12.13+1 more2025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
nvd
CVE-2024-38167P4MEDIUMCVSS 6.5≥ 17.6.0, < 17.6.18≥ 17.8.0, < 17.8.13+1 more2024-08-13
CVE-2024-38167 [MEDIUM] CWE-319 CVE-2024-38167: .NET and Visual Studio Information Disclosure Vulnerability .NET and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2023-36799P4MEDIUMCVSS 6.5≥ 17.2, < 17.2.19≥ 17.4, < 17.4.11+2 more2023-09-12
CVE-2023-36799 [MEDIUM] CWE-400 CVE-2023-36799: .NET Core and Visual Studio Denial of Service Vulnerability .NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-36897P4MEDIUMCVSS 6.5≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-36897 [MEDIUM] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability Visual Studio Tools for Office Runtime Spoofing Vulnerability
nvd
CVE-2023-32032P4MEDIUMCVSS 6.5≥ 17.0, < 17.0.22≥ 17.2, < 17.2.16+2 more2023-06-14
CVE-2023-32032 [MEDIUM] CWE-20 CVE-2023-32032: .NET and Visual Studio Elevation of Privilege Vulnerability .NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-21319P4MEDIUMCVSS 6.8≥ 17.2.0, < 17.2.23≥ 17.4.0, < 17.4.15+2 more2024-01-09
CVE-2024-21319 [MEDIUM] CWE-20 CVE-2024-21319: Microsoft Identity Denial of service vulnerability Microsoft Identity Denial of service vulnerability
nvd
Microsoft Visual Studio 2022 vulnerabilities | cvebase