CVE-2024-30052

MEDIUM

Microsoft Visual Studio - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-30052. PoCs published by ynwarcs.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2024-30052, which involves manipulating PDB (Program Database) files to embed malicious content. The builder tool generates a crafted executable with an embedded PDB file, likely exploiting a vulnerability in how the PDB file is processed.

Description

Visual Studio Remote Code Execution Vulnerability

Exploits (1)

nomisec WORKING POC 12 stars
by ynwarcs · poc
https://github.com/ynwarcs/CVE-2024-30052

This repository contains a functional exploit PoC for CVE-2024-30052, which involves manipulating PDB (Program Database) files to embed malicious content. The builder tool generates a crafted executable with an embedded PDB file, likely exploiting a vulnerability in how the PDB file is processed.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Microsoft Visual Studio 2022 (or related .NET tooling)
No auth needed
Prerequisites: Access to a system with Microsoft Visual Studio 2022 installed · Ability to compile and execute C# code
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0135
EPSS Percentile 67.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-693
Status published
Products (2)
microsoft/visual_studio_2019 15.0 - 15.9.63
microsoft/visual_studio_2022 17.4 - 17.4.20
Published Jun 11, 2024
Tracked Since Feb 18, 2026