Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
2025-06-13T02:15:29.180
2025-07-10T16:00:47.880
Analyzed
CVSSv3.1: 7.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | visual_studio_2022 | < 17.8.22 | Yes |
Application | microsoft | visual_studio_2022 | < 17.10.16 | Yes |
Application | microsoft | visual_studio_2022 | < 17.12.9 | Yes |
Application | microsoft | visual_studio_2022 | < 17.14.5 | Yes |