CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

visual_studio_2017

92 known vulnerabilities · sorted by CVSS score

CVE-2019-1352
HIGH8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.

microsoft / visual_studio_2017+1
Network
Published Jan 24, 2020
Page 1 of 5
CVE-2019-1349
HIGH8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

microsoft / visual_studio_2017+1
Network
Published Jan 24, 2020
CVE-2022-35826
HIGH8.8

Visual Studio Remote Code Execution Vulnerability

microsoft / visual_studio+7
Network
Published Aug 9, 2022
CVE-2019-1350
HIGH8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

microsoft / visual_studio_2017+1
Network
Published Jan 24, 2020
CVE-2022-35827
HIGH8.8

Visual Studio Remote Code Execution Vulnerability

microsoft / visual_studio+7
Network
Published Aug 9, 2022
CVE-2022-35777
HIGH8.8

Visual Studio Remote Code Execution Vulnerability

microsoft / visual_studio+6
Network
Published Aug 9, 2022
CVE-2025-21178
HIGH8.8

Visual Studio Remote Code Execution Vulnerability

microsoft / visual_studio_2017+5
Network
Published Jan 14, 2025
CVE-2025-49739
HIGH8.8

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

microsoft / visual_studio+6
Network
Published Jul 8, 2025
CVE-2019-0613
HIGH8.8

A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework and Visual Studio Remote Code Execution Vulnerability'.

microsoft / .net_framework+26
Network
Published Mar 5, 2019
CVE-2020-1416
HIGH8.8

An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.

microsoft / azure_storage_explorer+6
Network
Published Jul 14, 2020
CVE-2019-1113
HIGH8.8

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.

microsoft / .net_framework+23
Network
Published Jul 15, 2019
CVE-2019-1354
HIGH8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.

microsoft / visual_studio_2017+1
Network
Published Jan 24, 2020
CVE-2025-21176
HIGH8.8

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

microsoft / .net+19
Network
Published Jan 14, 2025
CVE-2022-35825
HIGH8.8

Visual Studio Remote Code Execution Vulnerability

microsoft / visual_studio+7
Network
Published Aug 9, 2022
CVE-2023-36897
HIGH8.1

Visual Studio Tools for Office Runtime Spoofing Vulnerability

microsoft / 365_apps+11
Network
Published Aug 8, 2023
CVE-2022-29148
HIGH7.8

Visual Studio Remote Code Execution Vulnerability

microsoft / visual_studio_2017
Local
Published May 10, 2022
CVE-2020-0810
HIGH7.8

An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system.An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.The update addresses the vulnerability by not permitting Diagnostics Hub Standard Collector or the Visual Studio Standard Collector to create files in arbitrary locations., aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'.

microsoft / visual_studio_2015+14
Local
Published Mar 12, 2020
CVE-2020-1257
HIGH7.8

An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1278, CVE-2020-1293.

microsoft / visual_studio+15
Local
Published Jun 9, 2020
CVE-2020-16856
HIGH7.8

<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted file with an affected version of Visual Studio.</p> <p>The update addresses the vulnerability by correcting how Visual Studio handles objects in memory.</p>

microsoft / visual_studio+5
Local
Published Sep 11, 2020
CVE-2023-21566
HIGH7.8

Visual Studio Elevation of Privilege Vulnerability

microsoft / visual_studio_2017+4
Local
Published Feb 14, 2023