VendorsMicrosoftvisual_studio_2017all versions
Vulnerabilities

Microsoft Visual Studio 2017

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

93CVEs
CVE-2020-0810
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system.An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.The update addresses the vulnerability by not permitting Diagnostics Hub Standard Collector or the Visual Studio Standard Collector to create files in arbitrary locations., aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.8EPSS 0.010
CVE-2018-8599
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability." This affects Microsoft Visual Studio, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-12-12 · Modified
7.8EPSS 0.010
CVE-2020-1133
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
7.8EPSS 0.010
CVE-2020-1202
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1203.
Published 2020-06-09 · Modified
7.8EPSS 0.009
CVE-2020-1203
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1202.
Published 2020-06-09 · Modified
7.8EPSS 0.009
CVE-2020-1393
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.
Published 2020-07-14 · Modified
7.8EPSS 0.009
CVE-2021-26434
Visual Studio Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.009
CVE-2021-42277
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.009
CVE-2019-1232
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
7.8EPSS 0.008
CVE-2022-41119
Visual Studio Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.008
CVE-2020-1257
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1278, CVE-2020-1293.
Published 2020-06-09 · Modified
7.8EPSS 0.008
CVE-2020-1278
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1293.
Published 2020-06-09 · Modified
7.8EPSS 0.008
CVE-2020-1293
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1278.
Published 2020-06-09 · Modified
7.8EPSS 0.008
CVE-2021-1651
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
7.8EPSS 0.008
CVE-2020-0793
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.8EPSS 0.008
CVE-2020-1130
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
7.8EPSS 0.008
CVE-2021-1680
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
7.8EPSS 0.007
CVE-2023-28296
Visual Studio Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
7.8EPSS 0.007
CVE-2022-21871
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
7.8EPSS 0.007
CVE-2021-27064
Visual Studio Installer Elevation of Privilege Vulnerability
Published 2021-04-13 · Modified
7.8EPSS 0.006
CVE-2023-21815
Visual Studio Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.8EPSS 0.005
CVE-2023-23381
Visual Studio Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.8EPSS 0.004
CVE-2024-43590
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
Published 2024-10-08 · Analyzed
7.8EPSS 0.004
CVE-2023-21566
Visual Studio Elevation of Privilege Vulnerability
Published 2023-02-14 · Modified
7.8EPSS 0.004
CVE-2019-1351
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
Published 2020-01-24 · Modified
7.5EPSS 0.087
CVE-2020-1597
ASP.NET Core Denial of Service Vulnerability
Published 2020-08-17 · Modified
7.5EPSS 0.066
CVE-2020-1108
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.063
CVE-2020-1161
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.051
CVE-2021-26423
.NET Core and Visual Studio Denial of Service Vulnerability
Published 2021-08-12 · Modified
7.5EPSS 0.039
CVE-2025-21172
.NET and Visual Studio Remote Code Execution Vulnerability
Published 2025-01-14 · Modified
7.5EPSS 0.018
CVE-2019-1211
Git for Visual Studio Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.3EPSS 0.017
CVE-2025-21206
Visual Studio Installer Elevation of Privilege Vulnerability
Published 2025-02-11 · Analyzed
7.3EPSS 0.007
CVE-2025-24998
Visual Studio Elevation of Privilege Vulnerability
Published 2025-03-11 · Analyzed
7.3EPSS 0.004
CVE-2025-55240
Visual Studio Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.3EPSS 0.004
CVE-2024-29060
Visual Studio Elevation of Privilege Vulnerability
Published 2024-06-11 · Modified
6.7EPSS 0.009
CVE-2019-1077
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Visual Studio Elevation of Privilege Vulnerability'.
Published 2019-07-15 · Modified
6.6EPSS 0.018
CVE-2021-1721
.NET Core and Visual Studio Denial of Service Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.033
CVE-2019-1425
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.033
CVE-2019-0757
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Published 2019-04-09 · Modified
6.5EPSS 0.027
CVE-2020-26870
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Published 2020-10-07 · Modified
6.1EPSS 0.049
← Prev2 / 3Next →