Visual Studio Remote Code Execution Vulnerability
CVE-2023-28296

7.8HIGH

Summary

A vulnerability exists in Visual Studio that could enable an attacker to execute arbitrary code on the system if a user opens a specially crafted file. This flaw poses significant risks to user environments, particularly if handled by individuals with limited security awareness. It is crucial for users to ensure their software is updated to mitigate potential exploits. For detailed information, visit the vendor advisory.

Affected Version(s)

Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Unknown 15.9.0 < 15.9.54

Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Unknown 16.11.0 < 16.11.26

Microsoft Visual Studio 2022 version 17.0 Unknown 17.0.0 < 17.0.21

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.