Microsoft Visual Studio
26 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Microsoft Visual Studio, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Microsoft Visual Studio CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High19
- Medium7
Latest CVEs
The 15 most recently published vulnerabilities affecting Microsoft Visual Studio.
- CVE-2024-38095.NET and Visual Studio Denial of Service Vulnerability7.5
- CVE-2023-32032.NET and Visual Studio Elevation of Privilege Vulnerability6.5
- CVE-2023-23381Visual Studio Remote Code Execution Vulnerability7.8
- CVE-2020-1393An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Wi...7.8
- CVE-2020-1293An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege...7.8
- CVE-2020-1278An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege...7.8
- CVE-2020-1257An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege...7.8
- CVE-2020-1203An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Sta...7.8
- CVE-2020-1202An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Sta...7.8
- CVE-2020-0900An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extension Installer Service Elevation of Pri...5.5
- CVE-2020-0810An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnera...7.8
- CVE-2020-0793An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege...7.8
- CVE-2019-1232An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service E...7.8
- CVE-2019-1113A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitra...8.8
- CVE-2019-1079An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.6.5
Product grouping is registry-driven, with AI assist and human review. How it works