msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDB file.
2014-05-20T23:55:05.277
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | debug_interface_access_software_development_kit | - | Yes |
Application | microsoft | visual_studio | ≤ 2012 | Yes |
Application | microsoft | visual_studio | 2002 | Yes |
Application | microsoft | visual_studio | 2003 | Yes |
Application | microsoft | visual_studio | 2005 | Yes |
Application | microsoft | visual_studio | 2010 | Yes |
Application | microsoft | visual_studio | 2010 | Yes |