Exposição de Microsoft Visual Studio

Development
13
score de exposição
2.347
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades catalogadas para o Microsoft Visual Studio reúne 23 CVEs, sem registros de severidade crítica, sem entradas no catálogo CISA KEV e sem novas ocorrências nos últimos 90 dias — indicadores que, em conjunto, apontam para um perfil de risco atualmente contido. A taxa de exploração ativa está abaixo da média geral do catálogo, o que sugere menor pressão ofensiva imediata em comparação com outras tecnologias rastreadas. Ainda assim, merece atenção o CVE-2018-8172, que apresenta o maior escore EPSS do conjunto (0,31), sinalizando probabilidade não desprezível de exploração mesmo tratando-se de uma vulnerabilidade mais antiga. Equipes de segurança que mantêm instalações do Visual Studio devem verificar a aplicação de correções para essa CVE e monitorar eventuais atualizações no panorama de ameaças, dado que vulnerabilidades de desenvolvimento frequentemente têm impacto na cadeia de entrega de software.

CVEs

23 resultados
CVE-2018-8172A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an uEPSS 32.8%CVE-2019-0546A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ construcEPSS 16.2%CVE-2019-0613A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markupEPSS 15.4%CVE-2019-1113A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who sEPSS 10.0%CVE-2019-0537An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicioEPSS 7.6%CVE-2018-0952An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "DiaEPSS 6.2%CVE-2019-1079An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio EPSS 6.1%CVE-2018-1037An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compilEPSS 5.9%CVE-2019-0657A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio EPSS 4.5%CVE-2019-0757A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGetEPSS 2.7%CVE-2018-8232A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tampering VulnerabEPSS 1.2%CVE-2019-0727An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows fiEPSS 1.0%CVE-2020-0810An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows fiEPSS 1.0%CVE-2018-8599An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operEPSS 1.0%CVE-2020-1202An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to pEPSS 0.9%CVE-2020-1203An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to pEPSS 0.9%CVE-2020-1393An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input,EPSS 0.9%CVE-2019-1232An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operEPSS 0.8%CVE-2020-1257An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'EPSS 0.8%CVE-2020-1278An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'EPSS 0.8%