Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
2025-05-13T17:16:02.903
2025-05-19T18:30:28.383
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | microsoft | visual_studio_2019 | < 16.11.47 | Yes |
| Application | microsoft | visual_studio_2022 | < 17.8.21 | Yes |
| Application | microsoft | visual_studio_2022 | < 17.10.14 | Yes |
| Application | microsoft | visual_studio_2022 | < 17.12.8 | Yes |
| Application | microsoft | visual_studio_2022 | < 17.13.7 | Yes |