Msrc Microsoft Visual Studio 2019 Version 16.11 vulnerabilities

106 known vulnerabilities affecting msrc/microsoft_visual_studio_2019_version_16.11.

Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH85MEDIUM17LOW1

Vulnerabilities

Page 6 of 6
CVE-2021-42319MEDIUMCVSS 4.72021-11-09
CVE-2021-42319 [MEDIUM] Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability Visual Studio: Visual Studio Microsoft: Microsoft Customer Action Required: Yes Impact: Elevation of Privilege Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely Remediation: Release Notes Reference: http://aka.ms/vs/15/release/latest Reference: https://docs.microsoft.
msrc
CVE-2020-1971HIGHCVSS 5.92021-10-12
CVE-2020-1971 [MEDIUM] OpenSSL: CVE-2020-1971 EDIPARTYNAME NULL pointer de-reference OpenSSL: CVE-2020-1971 EDIPARTYNAME NULL pointer de-reference FAQ: Why is this OpenSSL Software Foundation CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vulnerable. Please see Security Update
msrc
CVE-2021-3450HIGHCVSS 7.42021-10-12
CVE-2021-3450 [HIGH] OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT FAQ: Why is this OpenSSL Software Foundation CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vuln
msrc
CVE-2021-3449HIGHCVSS 5.92021-10-12
CVE-2021-3449 [MEDIUM] OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing FAQ: Why is this OpenSSL Software Foundation CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vulnerab
msrc
CVE-2021-41355MEDIUMCVSS 5.72021-10-12
CVE-2021-41355 [MEDIUM] .NET Core and Visual Studio Information Disclosure Vulnerability .NET Core and Visual Studio Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information. .NET Core & Visual Studio: .NET Core & Visual Studio Microsoft: Microsoft Impact: Information Disclosure Exploit Status: Publicly Disclose
msrc
CVE-2021-26434HIGHCVSS 7.82021-09-14
CVE-2021-26434 [HIGH] Visual Studio Elevation of Privilege Vulnerability Visual Studio Elevation of Privilege Vulnerability Visual Studio: Visual Studio Microsoft: Microsoft Impact: Elevation of Privilege Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A Remediation: Release Notes Reference: http://aka.ms/vs/15/release/latest Reference: https://my.visualstudio.com/Downloads?q=Visual S
msrc