Home/Product/microsoft visual studio 2017
Product

microsoft visual studio 2017

92 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-55240
>= 15.0 and < 15.9.77
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
7.3HIGH
CVE-2025-49739
>= 15.0 and < 15.9.75
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privile
8.8HIGH
CVE-2025-32703
>= 15.0 and < 15.9.73
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
5.5MEDIUM
CVE-2025-24998
>= 15.0 and < 15.9.71
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
7.3HIGH
CVE-2025-21206
>= 15.0 and < 15.9.70
Visual Studio Installer Elevation of Privilege Vulnerability
7.3HIGH
CVE-2025-21178
>= 15.0 and < 15.9.69
Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2025-21176
>= 15.0 and < 15.9.69
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2025-21172
>= 15.0 and <= 15.8
.NET and Visual Studio Remote Code Execution Vulnerability
7.5HIGH
CVE-2024-43603
>= 15.0.0 and < 15.9.67
Visual Studio Collector Service Denial of Service Vulnerability
5.5MEDIUM
CVE-2024-43590
>= 15.0 and < 15.9.67
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
7.8HIGH
CVE-2024-29060
>= 15.0 and < 15.9.63
Visual Studio Elevation of Privilege Vulnerability
6.7MEDIUM
CVE-2024-20656
>= 15.0 and < 15.9.59
Visual Studio Elevation of Privilege Vulnerability
7.8HIGH
CVE-2023-36796
>= 15.0 and < 15.9.57
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36794
>= 15.0 and < 15.9.57
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36793
>= 15.0 and < 15.9.57
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36792
>= 15.0 and < 15.9.57
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36897
>= 15.0 and < 15.9.56
Visual Studio Tools for Office Runtime Spoofing Vulnerability
8.1HIGH
CVE-2023-24897
>= 15.0 and <= 15.8
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-33139
>= 15.0 and < 15.8
Visual Studio Information Disclosure Vulnerability
5.5MEDIUM
CVE-2023-28299
>= 15.0 and < 15.9.54
Visual Studio Spoofing Vulnerability
5.5MEDIUM
CVE-2023-28296
>= 15.0 and < 15.9.54
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-23381
>= 15.0 and < 15.9.52
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21815
>= 15.0 and < 15.9.52
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21808
>= 15.0 and < 15.9.51
.NET and Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21567
>= 15.0 and < 15.9.52
Visual Studio Denial of Service Vulnerability
5.6MEDIUM
CVE-2023-21566
>= 15.0 and < 15.9.52
Visual Studio Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-41119
>= 15.0 and <= 15.9
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-35827
all versions
Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-35826
all versions
Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-35825
all versions
Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-35777
>= 15.0 and <= 15.9
Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-29148
>= 15.0 and < 15.9.48
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-24767
>= 15.0 and < 15.9.46
GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
7.8HIGH
CVE-2022-21871
>= 15.0 and < 15.9.44
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
7.0HIGH
CVE-2021-42319
>= 15.0 and <= 15.9
Visual Studio Elevation of Privilege Vulnerability
4.7MEDIUM
CVE-2021-42277
>= 15.0 and <= 15.9
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
5.5MEDIUM
CVE-2021-36952
>= 15.0 and <= 15.9
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2021-26434
>= 15.0 and <= 15.9
Visual Studio Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-34485
>= 15.0 and <= 15.9
.NET Core and Visual Studio Information Disclosure Vulnerability
5.0MEDIUM
CVE-2021-26423
>= 15.0 and <= 15.9
.NET Core and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2021-28322
>= 15.0 and <= 15.9
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-28321
>= 15.0 and <= 15.9
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-28313
>= 15.0 and <= 15.9
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-27064
>= 15.0 and <= 15.9
Visual Studio Installer Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-1721
>= 15.0 and <= 15.9
.NET Core and Visual Studio Denial of Service Vulnerability
6.5MEDIUM
CVE-2021-1639
>= 15.0 and <= 15.9
Visual Studio Code Remote Code Execution Vulnerability
7.0HIGH
CVE-2021-1680
>= 15.0 and <= 15.8
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-1651
>= 15.0 and < 15.9
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8HIGH
CVE-2020-17156
>= 15.0 and <= 15.9
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2020-17100
>= 15.0 and <= 15.9
Visual Studio Tampering Vulnerability
5.5MEDIUM
CVE-2020-26870
all versions
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return th
6.1MEDIUM
CVE-2020-1133
>= 15.0 and < 15.9.27
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations.
5.5MEDIUM
CVE-2020-1130
>= 15.0 and < 15.9.27
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations.
6.6MEDIUM
CVE-2020-16874
>= 15.0 and <= 15.8
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who suc
7.8HIGH
CVE-2020-16856
>= 15.0 and <= 15.8
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who suc
7.8HIGH
CVE-2020-1597
>= 15.0 and <= 15.8
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited
7.5HIGH
CVE-2020-1416
>= 15.0 and < 15.9.25
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka '
8.8HIGH
CVE-2020-1393
>= 15.0 and < 15.9.25
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanit
7.8HIGH
CVE-2020-1147
>= 15.0 and <= 15.9
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to
7.8HIGH
CVE-2020-1293
>= 15.0 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8HIGH
CVE-2020-1278
>= 15.0 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8HIGH
CVE-2020-1257
>= 15.0 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8HIGH
CVE-2020-1203
>= 15.0 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8HIGH
CVE-2020-1202
>= 15.0 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8HIGH
CVE-2020-1161
>= 15.1 and <= 15.9
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2020-1108
all versions
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET F
7.5HIGH
CVE-2020-0900
all versions
An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operatio
5.5MEDIUM
CVE-2020-0899
all versions
An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, a
5.5MEDIUM
CVE-2020-0884
>= 15.1 and <= 15.8
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft V
3.7LOW
CVE-2020-0810
>= 15.1 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8HIGH
CVE-2020-0793
>= 15.1 and <= 15.9
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8HIGH
CVE-2019-1354
>= 15.0 and < 15.9.18
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8HIGH
CVE-2019-1352
>= 15.0 and < 15.9.18
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8HIGH
CVE-2019-1351
>= 15.0 and < 15.9.18
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tam
7.5HIGH
CVE-2019-1350
>= 15.0 and < 15.9.18
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8HIGH
CVE-2019-1349
>= 15.0 and < 15.9.18
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8HIGH
CVE-2019-1425
all versions
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived f
6.5MEDIUM
CVE-2019-1232
all versions
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain
7.8HIGH
CVE-2019-1211
all versions
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker
7.3HIGH
CVE-2019-1113
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8HIGH
CVE-2019-1077
all versions
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Vi
5.0MEDIUM
CVE-2019-0727
all versions
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8HIGH
CVE-2019-0809
all versions
A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input befor
7.8HIGH
CVE-2019-0757
all versions
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modi
6.5MEDIUM
CVE-2019-0657
all versions
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visu
5.9MEDIUM
CVE-2019-0613
all versions
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the sou
8.8HIGH
CVE-2019-0546
all versions
A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C+
7.8HIGH
CVE-2018-8599
all versions
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain
7.8HIGH
CVE-2018-0952
all versions
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations
7.8HIGH
CVE-2018-8232
all versions
A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tamperin
7.8HIGH
CVE-2018-8172
all versions
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a fil
7.8HIGH
CVE-2018-1037
all versions
An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory wh
4.3MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin