threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft visual studio 2019
Product
microsoft visual studio 2019
118 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-55240
>= 16.0 and < 16.11.52
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-49739
>= 16.0 and < 16.11.49
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privile
8.8
HIGH
CVE-2025-32703
>= 16.0 and < 16.11.47
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-32702
>= 16.0 and < 16.11.47
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attack
7.8
HIGH
CVE-2025-25003
>= 16.0 and < 16.11.45
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-24998
>= 16.0 and < 16.11.45
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-21206
>= 16.0 and < 16.11.44
Visual Studio Installer Elevation of Privilege Vulnerability
7.3
HIGH
CVE-2025-21178
>= 16.0 and < 16.11.43
Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21172
>= 16.0 and <= 16.10
.NET and Visual Studio Remote Code Execution Vulnerability
7.5
HIGH
CVE-2024-43603
>= 16.0.0 and < 16.11.41
Visual Studio Collector Service Denial of Service Vulnerability
5.5
MEDIUM
CVE-2024-43590
>= 15.0 and < 15.9.67
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-30052
>= 15.0 and < 15.9.63
Visual Studio Remote Code Execution Vulnerability
4.7
MEDIUM
CVE-2024-29060
>= 16.0 and < 16.11.37
Visual Studio Elevation of Privilege Vulnerability
6.7
MEDIUM
CVE-2024-28938
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28937
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28936
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28935
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28934
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28933
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28932
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28931
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28930
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-28929
>= 16.0 and < 16.11.35
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-20656
>= 16.0 and < 16.11.33
Visual Studio Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2023-36042
>= 16.0 and < 16.11.32
Visual Studio Denial of Service Vulnerability
6.2
MEDIUM
CVE-2023-36796
>= 16.0 and < 16.11.30
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36794
>= 16.0 and < 16.11.30
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36793
>= 16.0 and < 16.11.30
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36792
>= 16.0 and < 16.11.30
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36759
>= 16.0 and < 16.11.30
Visual Studio Elevation of Privilege Vulnerability
6.7
MEDIUM
CVE-2023-36897
>= 16.0 and < 16.11.29
Visual Studio Tools for Office Runtime Spoofing Vulnerability
8.1
HIGH
CVE-2023-24897
>= 16.0 and <= 16.10
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-33139
>= 16.0 and <= 16.10
Visual Studio Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2023-28299
>= 16.0 and < 16.11.26
Visual Studio Spoofing Vulnerability
5.5
MEDIUM
CVE-2023-28296
>= 16.0 and < 16.11.26
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-28263
>= 16.0 and < 16.11.26
Visual Studio Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2023-28262
>= 16.0 and < 16.11.26
Visual Studio Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2023-23381
>= 16.0 and < 16.11.24
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-21815
>= 16.0 and < 16.11.24
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-21808
>= 16.0 and < 16.11.24
.NET and Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-21567
>= 16.0 and < 16.11.24
Visual Studio Denial of Service Vulnerability
5.6
MEDIUM
CVE-2023-21566
>= 16.0 and < 16.11.24
Visual Studio Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-41119
>= 16.0 and <= 16.11
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-41032
>= 16.0.0 and < 16.9.26
NuGet Client Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-38013
all versions
.NET Core and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2022-35827
all versions
Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-35826
all versions
Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-35825
all versions
Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-35777
>= 16.0 and <= 16.11
Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-30184
>= 16.0 and < 16.9.22
.NET and Visual Studio Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-29145
>= 16.0 and < 16.9.21
.NET and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2022-29117
>= 16.0 and <= 16.0.11
.NET and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2022-23267
>= 16.0 and < 16.9.21
.NET and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2022-24513
>= 15.9 and <= 16.9
Visual Studio Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24767
>= 16.0 and < 16.7.27
GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
7.8
HIGH
CVE-2022-24512
>= 16.0 and <= 16.6.4
.NET and Visual Studio Remote Code Execution Vulnerability
6.3
MEDIUM
CVE-2022-24464
>= 16.0 and <= 16.6.4
.NET and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2022-21986
>= 16.0 and <= 16.11
.NET Denial of Service Vulnerability
7.5
HIGH
CVE-2022-21871
>= 16.0 and < 16.7.25
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
7.0
HIGH
CVE-2021-43877
all versions
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-42319
>= 16.0 and <= 16.11
Visual Studio Elevation of Privilege Vulnerability
4.7
MEDIUM
CVE-2021-42277
>= 16.0 and <= 16.11
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
5.5
MEDIUM
CVE-2021-41355
>= 16.0 and <= 16.11
.NET Core and Visual Studio Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2021-36952
>= 16.0 and <= 16.7
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-26434
>= 16.0 and <= 16.11
Visual Studio Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34532
>= 16.0 and <= 16.10
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34485
>= 16.0 and <= 16.10
.NET Core and Visual Studio Information Disclosure Vulnerability
5.0
MEDIUM
CVE-2021-26423
>= 16.0 and <= 16.10
.NET Core and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2021-31957
>= 16.0 and <= 16.10
ASP.NET Core Denial of Service Vulnerability
5.9
MEDIUM
CVE-2021-31204
>= 16.0 and < 16.4.22
.NET and Visual Studio Elevation of Privilege Vulnerability
7.3
HIGH
CVE-2021-27068
>= 16.0 and < 16.4.22
Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28322
>= 16.0 and <= 16.7
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28321
>= 16.0 and <= 16.7
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28313
>= 16.0 and <= 16.7
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-27064
>= 16.0 and <= 16.4
Visual Studio Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26701
>= 16.0 and <= 16.9
.NET Core Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-24112
all versions
.NET Core Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-1721
>= 16.0 and <= 16.8
.NET Core and Visual Studio Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-1639
>= 16.0 and <= 16.8
Visual Studio Code Remote Code Execution Vulnerability
7.0
HIGH
CVE-2021-1723
>= 16.0 and <= 16.8
ASP.NET Core and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2021-1680
>= 16.0 and <= 16.7.0
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1651
>= 16.0 and < 16.4
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17156
>= 16.0 and <= 16.8
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2020-17100
>= 16.0 and <= 16.6
Visual Studio Tampering Vulnerability
5.5
MEDIUM
CVE-2020-26870
all versions
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return th
6.1
MEDIUM
CVE-2020-8927
>= 16.0 and <= 16.11
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-sh
5.3
MEDIUM
CVE-2020-1133
>= 16.0 and < 16.4.13
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations.
5.5
MEDIUM
CVE-2020-1130
>= 16.0 and < 16.4.13
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations.
6.6
MEDIUM
CVE-2020-16874
>= 16.0 and <= 16.3
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who suc
7.8
HIGH
CVE-2020-16856
>= 16.0 and <= 16.3
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who suc
7.8
HIGH
CVE-2020-1597
>= 16.0 and <= 16.3
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited
7.5
HIGH
CVE-2020-1416
>= 16.0 and < 16.0.16
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka '
8.8
HIGH
CVE-2020-1393
>= 16.0 and < 16.4.11
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanit
7.8
HIGH
CVE-2020-1147
>= 16.0 and <= 16.6
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to
7.8
HIGH
CVE-2020-1293
>= 16.0 and <= 16.6
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8
HIGH
CVE-2020-1278
>= 16.0 and <= 16.6
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8
HIGH
CVE-2020-1257
>= 16.0 and <= 16.6
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8
HIGH
CVE-2020-1203
>= 16.0 and <= 16.6
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8
HIGH
CVE-2020-1202
>= 16.0 and <= 16.6
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8
HIGH
CVE-2020-1161
>= 16.0 and <= 16.5
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2020-1108
all versions
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET F
7.5
HIGH
CVE-2020-0900
all versions
An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operatio
5.5
MEDIUM
CVE-2020-0899
all versions
An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, a
5.5
MEDIUM
CVE-2020-0884
>= 16.0 and <= 16.3
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft V
3.7
LOW
CVE-2020-0810
>= 16.0 and <= 16.4
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8
HIGH
CVE-2020-0793
>= 16.0 and <= 16.4
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operati
7.8
HIGH
CVE-2020-0789
>= 16.0 and <= 16.4
A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Vi
7.1
HIGH
CVE-2019-1354
>= 16.0 and < 16.4.1
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8
HIGH
CVE-2019-1352
>= 16.0 and < 16.4.1
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8
HIGH
CVE-2019-1351
>= 16.0 and < 16.4.1
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tam
7.5
HIGH
CVE-2019-1350
>= 16.0 and < 16.4.1
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8
HIGH
CVE-2019-1349
>= 16.0 and < 16.4.1
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Rem
8.8
HIGH
CVE-2019-1486
>= 16.0 and <= 16.4
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arb
6.1
MEDIUM
CVE-2019-1425
all versions
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived f
6.5
MEDIUM
CVE-2019-1232
all versions
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain
7.8
HIGH
CVE-2019-1211
all versions
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker
7.3
HIGH
CVE-2019-1077
all versions
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Vi
5.0
MEDIUM
CVE-2019-0727
all versions
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector
7.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin