Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft Visual Studio 2015 Update 3.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-49739HIGH | Visual Studio Elevation of Privilege VulnerabilityImproper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. CWE-59Jul 8, 2025 | CVSS8.8v3.1 | EPSS0.771% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21172HIGH | .NET and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio. … | CVSS7.5v3.1 | EPSS1.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21178HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability | CVSS8.8v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21176HIGH | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio. … CWE-126Jan 14, 2025 | CVSS8.8v3.1 | EPSS2.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43603MEDIUM | Visual Studio Collector Service Denial of Service VulnerabilityVisual Studio Collector Service Denial of Service Vulnerability CWE-59Oct 8, 2024 | CVSS5.5v3.1 | EPSS0.767% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-20656HIGH | Visual Studio Elevation of Privilege VulnerabilityVisual Studio Elevation of Privilege Vulnerability CWE-59Jan 9, 2024 | CVSS7.8v3.1 | EPSS3.91% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-36796HIGH | Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2023-36796: .NET Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in Microsoft.DiaSymReader.Native.amd64.dll when reading a corrupted PDB file which may lead to … CWE-191Sep 12, 2023 | CVSS7.8v3.1 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24897HIGH | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2023-24897: .NET Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. This security update addresses a vulnerability in the MSDIA SDK where corrupted PDBs can cause heap overflow, leading … CWE-122Jun 14, 2023 | CVSS7.8v3.1 | EPSS1.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33139MEDIUM | Visual Studio Information Disclosure VulnerabilityVisual Studio Information Disclosure Vulnerability CWE-125Jun 13, 2023 | CVSS5.5v3.1 | EPSS0.824% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-23381HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability CWE-122Feb 14, 2023 | CVSS7.8v3.1 | EPSS0.436% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21815HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability CWE-191Feb 14, 2023 | CVSS7.8v3.1 | EPSS0.523% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21808HIGH | .NET and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2023-21808: .NET Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in how .NET reads debugging symbols, where reading a malicious symbols file may result in remo… CWE-416Feb 14, 2023 | CVSS7.8v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35827HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35777, CVE-2022-35825, CVE-2022-35826. Aug 9, 2022 | CVSS8.8v3.1 | EPSS2.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35826HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35777, CVE-2022-35825, CVE-2022-35827. Aug 9, 2022 | CVSS8.8v3.1 | EPSS2.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35825HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35777, CVE-2022-35826, CVE-2022-35827. Aug 9, 2022 | CVSS8.8v3.1 | EPSS2.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35777HIGH | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35825, CVE-2022-35826, CVE-2022-35827. CWE-94Aug 9, 2022 | CVSS8.8v3.1 | EPSS2.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-21871HIGH | Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege VulnerabilityMicrosoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability. CWE-269Jan 11, 2022 | CVSS7.0v3.1 | EPSS0.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42277MEDIUM | Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityDiagnostics Hub Standard Collector Elevation of Privilege Vulnerability CWE-269Nov 10, 2021 | CVSS5.5v3.1 | EPSS0.792% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28322HIGH | Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityDiagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28313, CVE-2021-28321. CWE-269Apr 13, 2021 | CVSS7.8v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28321HIGH | Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityDiagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28313, CVE-2021-28322. | CVSS7.8v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28313HIGH | Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityDiagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28321, CVE-2021-28322. CWE-269Apr 13, 2021 | CVSS7.8v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-1680HIGH | Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityDiagnostics Hub Standard Collector Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1651. CWE-269Jan 12, 2021 | CVSS7.8v3.1 | EPSS0.714% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-1651HIGH | Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityDiagnostics Hub Standard Collector Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1680. CWE-269Jan 12, 2021 | CVSS7.8v3.1 | EPSS0.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1130MEDIUM | Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1133. CWE-269Sep 11, 2020 | CVSS6.6v3.1 | EPSS0.777% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1133MEDIUM | Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1130. CWE-269Sep 11, 2020 | CVSS5.5v3.1 | EPSS0.978% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |