📦 Visual Studio 2022

by Microsoft

🔍 What is Visual Studio 2022?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55315

CRITICAL CVSS 9.9 Oct 14, 2025

CVE-2025-55315 is an HTTP request smuggling vulnerability in ASP.NET Core that allows an authenticated attacker to bypass security features by manipulating HTTP request/response sequences. This affect...

CVE-2024-0057

CRITICAL CVSS 9.1 Jan 9, 2024

This vulnerability allows attackers to bypass security features in .NET, .NET Framework, and Visual Studio, potentially enabling unauthorized access or privilege escalation. It affects systems running...

CVE-2025-55240

HIGH CVSS 7.3 Oct 14, 2025

This vulnerability allows an authorized attacker with local access to a system running Visual Studio to elevate their privileges beyond what they should have. It affects users of Microsoft Visual Stud...

CVE-2025-30399

HIGH CVSS 7.5 Jun 13, 2025

This CVE describes an untrusted search path vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code by manipulating the search order for DLLs or other files. Attackers ...

CVE-2025-26646

HIGH CVSS 8.0 May 13, 2025

This vulnerability allows an authorized attacker to control file names or paths in .NET, Visual Studio, and Build Tools for Visual Studio, enabling network-based spoofing attacks. It affects systems r...

CVE-2025-29802

HIGH CVSS 7.3 Apr 8, 2025

This vulnerability allows an authenticated attacker with local access to a system running Visual Studio to bypass intended access controls and elevate privileges. It affects users running vulnerable v...

CVE-2025-26682

HIGH CVSS 7.5 Apr 8, 2025

This CVE describes a resource exhaustion vulnerability in ASP.NET Core where an attacker can send specially crafted requests to consume excessive server resources without proper throttling. This allow...

CVE-2025-25003

HIGH CVSS 7.3 Mar 11, 2025

This vulnerability allows an authorized attacker to exploit an uncontrolled search path element in Visual Studio to execute arbitrary code with elevated privileges on the local system. It affects user...

CVE-2025-24998

HIGH CVSS 7.3 Mar 11, 2025

This vulnerability allows an authorized attacker to exploit an uncontrolled search path element in Visual Studio to execute arbitrary code with elevated privileges. It affects users running vulnerable...

CVE-2025-21206

HIGH CVSS 7.3 Feb 11, 2025

This vulnerability in Visual Studio Installer allows attackers to elevate privileges on Windows systems. An authenticated attacker could execute arbitrary code with SYSTEM privileges by exploiting imp...

CVE-2025-21405

HIGH CVSS 7.3 Jan 14, 2025

This CVE describes an elevation of privilege vulnerability in Visual Studio that allows authenticated attackers to gain higher privileges than intended. It affects developers and organizations using V...

CVE-2025-21171

HIGH CVSS 7.5 Jan 14, 2025

This .NET vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow. It affects systems running vulnerable versions of .NET Framewo...

CVE-2025-21172

HIGH CVSS 7.5 Jan 14, 2025

This CVE describes a heap-based buffer overflow vulnerability in .NET and Visual Studio that could allow remote code execution. Attackers could exploit this by tricking users into opening specially cr...

CVE-2025-21173

HIGH CVSS 7.3 Jan 14, 2025

This CVE describes a privilege escalation vulnerability in .NET that allows authenticated attackers to elevate their privileges on affected systems. It affects systems running vulnerable versions of ....

CVE-2025-21178

HIGH CVSS 8.8 Jan 14, 2025

This is a heap-based buffer overflow vulnerability in Visual Studio that allows remote code execution when processing specially crafted files. Attackers could exploit this to execute arbitrary code wi...

CVE-2024-43483

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability in .NET, .NET Framework, and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected applications. It affects systems running v...

CVE-2024-43485

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests that trigger inefficient algorithmic complexity. It affects systems run...

CVE-2024-38168

HIGH CVSS 7.5 Aug 13, 2024

This CVE describes a denial of service vulnerability in .NET and Visual Studio where an attacker can cause affected systems to become unresponsive or crash. The vulnerability affects systems running v...

CVE-2024-38095

HIGH CVSS 7.5 Jul 9, 2024

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. It affects applications built with vulnerable .NET...

CVE-2024-38081

HIGH CVSS 7.3 Jul 9, 2024

This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, or Visual Studio installations. An authenticated attacker could exploit this to gain higher ...

CVE-2024-28936

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code by sending specially crafted requests to affected systems. It affects applications and serv...

CVE-2024-28938

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using vu...

CVE-2024-28932

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using vu...

CVE-2024-28934

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using vu...

CVE-2024-28930

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using vu...

CVE-2024-21409

HIGH CVSS 7.3 Apr 9, 2024

This vulnerability allows remote code execution in .NET, .NET Framework, and Visual Studio through a use-after-free memory corruption issue (CWE-416). Attackers can exploit this to execute arbitrary c...

CVE-2024-26190

HIGH CVSS 7.5 Mar 12, 2024

This vulnerability in Microsoft's QUIC protocol implementation allows attackers to cause denial of service by sending specially crafted network packets. It affects systems running Microsoft Windows wi...

CVE-2024-21392

HIGH CVSS 7.5 Mar 12, 2024

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. It affects applications built with vulnerable .NET...

CVE-2024-20656

HIGH CVSS 7.8 Jan 9, 2024

This CVE describes an elevation of privilege vulnerability in Visual Studio that allows authenticated attackers to gain SYSTEM-level privileges on affected Windows systems. It affects users running vu...

CVE-2023-36038

HIGH CVSS 8.2 Nov 14, 2023

This vulnerability in ASP.NET Core allows attackers to cause denial of service by sending specially crafted requests that consume excessive resources. It affects ASP.NET Core applications running on W...

CVE-2023-36049

HIGH CVSS 7.6 Nov 14, 2023

This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, and Visual Studio versions. An authenticated attacker could exploit this to gain higher priv...

CVE-2023-38171

HIGH CVSS 7.5 Oct 10, 2023

This vulnerability in Microsoft's QUIC protocol implementation allows attackers to cause denial of service by sending specially crafted network packets. It affects Windows systems running QUIC-enabled...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2023-36796

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability in Visual Studio allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted file. It affects developers and organizations usin...

CVE-2023-36793

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability allows remote code execution in Visual Studio when processing specially crafted files. Attackers could exploit this to run arbitrary code on affected systems. Users running vulnerab...

CVE-2023-38180

HIGH CVSS 7.5 Aug 8, 2023

This CVE describes a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending specially crafted requests. It affects systems running vu...

CVE-2023-36897

HIGH CVSS 8.1 Aug 8, 2023

This vulnerability in Visual Studio Tools for Office Runtime allows attackers to spoof file paths, potentially tricking users into opening malicious files. It affects systems running vulnerable versio...

CVE-2023-35390

HIGH CVSS 7.8 Aug 8, 2023

CVE-2023-35390 is a remote code execution vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code on affected systems. The vulnerability affects systems running vulnera...

CVE-2023-33170

HIGH CVSS 8.1 Jul 11, 2023

This vulnerability allows attackers to bypass security features in ASP.NET and Visual Studio, potentially enabling unauthorized access or privilege escalation. It affects systems running vulnerable ve...

CVE-2023-24895

HIGH CVSS 7.8 Jun 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a flaw in .NET, .NET Framework, and Visual Studio. It affects systems running vulnerable versions...

CVE-2023-33126

HIGH CVSS 7.3 Jun 14, 2023

CVE-2023-33126 is a remote code execution vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code on affected systems. This affects systems running vulnerable versions ...

CVE-2023-28260

HIGH CVSS 7.8 Apr 11, 2023

CVE-2023-28260 is a .NET DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing malicious DLLs in specific directories. This affects .NET applications running on Window...

CVE-2025-62214

MEDIUM CVSS 6.7 Nov 11, 2025

This command injection vulnerability in Visual Studio allows authenticated attackers to execute arbitrary code on the local system by injecting malicious commands. It affects developers and organizati...

CVE-2025-55248

MEDIUM CVSS 4.8 Oct 14, 2025

This vulnerability involves inadequate encryption strength in .NET, .NET Framework, and Visual Studio, allowing an authorized attacker to disclose sensitive information over a network. It affects syst...

CVE-2025-32703

MEDIUM CVSS 5.5 May 13, 2025

This vulnerability in Visual Studio allows authenticated local attackers to bypass access controls and access sensitive information they shouldn't have permission to view. It affects users running vul...

CVE-2024-49044

MEDIUM CVSS 6.7 Nov 12, 2024

This CVE describes an elevation of privilege vulnerability in Visual Studio that allows authenticated attackers to gain higher privileges than intended. It affects developers and organizations using V...

CVE-2024-38167

MEDIUM CVSS 6.5 Aug 13, 2024

This vulnerability in .NET and Visual Studio allows attackers to read sensitive information from memory that should be protected. It affects applications built with vulnerable .NET versions and develo...

CVE-2024-29060

MEDIUM CVSS 6.7 Jun 11, 2024

This CVE describes an elevation of privilege vulnerability in Visual Studio that allows authenticated attackers to gain higher privileges than intended. It affects users running vulnerable versions of...

CVE-2024-30046

MEDIUM CVSS 5.9 May 14, 2024

This CVE describes a denial of service vulnerability in Visual Studio where a race condition (CWE-362) could allow an attacker to crash the application. This affects developers and organizations using...