A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2017 to the latest version in the current channel channel.Update Microsoft Visual Studio 2015 to the latest version in the LTSC 14.0 version stream, or upgrade to a newer supported version of Visual Studio 2015. | Jun 25, 2025 | Jul 10, 2018 |
| Msft | — | Security Update for the remote code execution vulnerability in Visual Studio 2015 Update 3 (KB4336999)Security Update for the remote code execution vulnerability in Visual Studio 2012 Update 5 (KB4336946)Security Update for the remote code execution vulnerability in Visual Studio 2013 Update 5 (KB4336986)Security Update for the remote code execution vulnerability in Visual Studio 2010 Service Pack 1 Update 3 (KB4336919) | Nov 2, 2018 | Jul 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub