An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the current channel channel.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2015 to the latest version in the LTSC 14.0 version stream, or upgrade to a newer supported version of Visual Studio 2015. | Jun 25, 2025 | Apr 10, 2018 |
| Msft | — | Security Update for the information disclosure vulnerability in Visual Studio 2012 Update 5 (KB4089501)Security Update for the information disclosure vulnerability in Visual Studio 2015 Update 3 (KB4087371)Security Update for the information disclosure vulnerability in Visual Studio 2010 Service Pack 1 Update 3 (KB4091346)Security Update for the information disclosure vulnerability in Visual Studio 2013 Update 5 (KB4089283) | Sep 13, 2018 | Apr 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub