Visual Studio 2022 Microsoft Visual Studio 2022

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Visual Studio 2022.

By the Year

In 2026 there have been 22 vulnerabilities in Microsoft Visual Studio 2022 with an average score of 7.6 out of ten. Last year, in 2025 Visual Studio 2022 had 24 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Visual Studio 2022 in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.12.




Year Vulnerabilities Average Score
2026 22 7.59
2025 24 7.48
2024 38 7.77
2023 37 7.27
2022 17 7.71
2021 1 8.80
2020 1 5.30

It may take a day or so for new Visual Studio 2022 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Visual Studio 2022 Security Vulnerabilities

Jul 2026: .NET Spoofing Vulnerability
CVE-2026-50659 6.5 - Medium - July 14, 2026

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

Output Sanitization

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-50651 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: .NET Framework Elevation of Privilege Vulnerability
CVE-2026-50650 7.8 - High - July 14, 2026

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Code Injection

Jul 2026: .NET Remote Code Execution Vulnerability
CVE-2026-50649 7.8 - High - July 14, 2026

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

Marshaling, Unmarshaling

Jul 2026: .NET Framework Denial of Service Vulnerability
CVE-2026-50648 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: .NET Framework Remote Code Execution Vulnerability
CVE-2026-50646 7.8 - High - July 14, 2026

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

Protection Mechanism Failure

Jul 2026: .NET Framework Denial of Service Vulnerability
CVE-2026-50527 7.5 - High - July 14, 2026

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

Stack Overflow

Jul 2026: .NET Security Feature Bypass Vulnerability
CVE-2026-50528 8.2 - High - July 14, 2026

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

AuthZ

Jul 2026: .NET Tampering Vulnerability
CVE-2026-50526 7 - High - July 14, 2026

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

insecure temporary file

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-50525 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: .NET Framework Denial of Service Vulnerability
CVE-2026-50524 7.5 - High - July 14, 2026

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

Improper Validation of Specified Type of Input

Jul 2026: Visual Studio Remote Code Execution Vulnerability
CVE-2026-47305 7.8 - High - July 14, 2026

Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

Protection Mechanism Failure

Jul 2026: .NET Security Feature Bypass Vulnerability
CVE-2026-47304 8.1 - High - July 14, 2026

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

Improper Verification of Cryptographic Signature

Jul 2026: ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-47303 8.8 - High - July 14, 2026

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Authentication Bypass by Assumed-Immutable Data

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-47302 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-47300 8.8 - High - July 14, 2026

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Incorrect Implementation of Authentication Algorithm

May 2026: .NET Core Tampering Vulnerability
CVE-2026-32175 4.3 - Medium - May 12, 2026

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Absolute Path Traversal

May 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-32177 7.3 - High - May 12, 2026

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Apr 2026: .NET and Visual Studio Denial of Service Vulnerability
CVE-2026-32203 7.5 - High - April 14, 2026

Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.

Stack Overflow

Apr 2026: .NET Spoofing Vulnerability
CVE-2026-32178 7.5 - High - April 14, 2026

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

Improper Neutralization of Special Elements

Feb 2026: GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability
CVE-2026-21257 8 - High - February 10, 2026

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.

Command Injection

Feb 2026: GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
CVE-2026-21256 8.8 - High - February 10, 2026

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.

Command Injection

Nov 2025: Visual Studio Remote Code Execution Vulnerability
CVE-2025-62214 6.7 - Medium - November 11, 2025

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.

Command Injection

Oct 2025: .NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
CVE-2025-55248 4.8 - Medium - October 14, 2025

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Inadequate Encryption Strength

Oct 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-55240 7.3 - High - October 14, 2025

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Authorization

Oct 2025: ASP.NET Security Feature Bypass Vulnerability
CVE-2025-55315 9.9 - Critical - October 14, 2025

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

HTTP Request Smuggling

Aug 2025: GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
CVE-2025-53773 7.8 - High - August 12, 2025

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

Command Injection

Jul 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-49739 8.8 - High - July 08, 2025

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

insecure temporary file

Jun 2025: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2025-30399 7.5 - High - June 13, 2025

Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

Untrusted Path

Jun 2025: Visual Studio Remote Code Execution Vulnerability
CVE-2025-47959 7.1 - High - June 13, 2025

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.

Command Injection

May 2025: .NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
CVE-2025-26646 8 - High - May 13, 2025

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

External Control of File Name or Path

May 2025: Visual Studio Remote Code Execution Vulnerability
CVE-2025-32702 7.8 - High - May 13, 2025

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

Command Injection

May 2025: Visual Studio Information Disclosure Vulnerability
CVE-2025-32703 5.5 - Medium - May 13, 2025

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

Insufficient Granularity of Access Control

Apr 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-29802 7.3 - High - April 08, 2025

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

DLL preloading

Apr 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-29804 7.3 - High - April 08, 2025

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Authorization

Apr 2025: ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2025-26682 7.5 - High - April 08, 2025

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Mar 2025: ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
CVE-2025-24070 7 - High - March 11, 2025

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

1390

Mar 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-24998 7.3 - High - March 11, 2025

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

DLL preloading

Mar 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-25003 7.3 - High - March 11, 2025

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

DLL preloading

Feb 2025: Visual Studio Installer Elevation of Privilege Vulnerability
CVE-2025-21206 7.3 - High - February 11, 2025

Visual Studio Installer Elevation of Privilege Vulnerability

DLL preloading

Jan 2025: Visual Studio Elevation of Privilege Vulnerability
CVE-2025-21405 7.3 - High - January 14, 2025

Visual Studio Elevation of Privilege Vulnerability

Authorization

Jan 2025: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVE-2025-21176 8.8 - High - January 14, 2025

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Buffer Over-read

Jan 2025: Visual Studio Remote Code Execution Vulnerability
CVE-2025-21178 8.8 - High - January 14, 2025

Visual Studio Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Jan 2025: .NET Elevation of Privilege Vulnerability
CVE-2025-21173 7.3 - High - January 14, 2025

.NET Elevation of Privilege Vulnerability

Creation of Temporary File in Directory with Insecure Permissions

Jan 2025: .NET Remote Code Execution Vulnerability
CVE-2025-21171 7.5 - High - January 14, 2025

.NET Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Jan 2025: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2025-21172 7.5 - High - January 14, 2025

.NET and Visual Studio Remote Code Execution Vulnerability

Integer Overflow or Wraparound

Visual Studio Elevation of Privilege Vulnerability
CVE-2024-49044 6.7 - Medium - November 12, 2024

Visual Studio Elevation of Privilege Vulnerability

Authorization

DoS Vulnerability in .NET Runtime for Visual Studio
CVE-2024-43499 7.5 - High - November 12, 2024

.NET and Visual Studio Denial of Service Vulnerability

Data Amplification

Microsoft .NET/VS Remote Code Execution Vulnerability
CVE-2024-43498 9.8 - Critical - November 12, 2024

.NET and Visual Studio Remote Code Execution Vulnerability

Object Type Confusion

Oct 2024: Visual Studio Collector Service Denial of Service Vulnerability
CVE-2024-43603 5.5 - Medium - October 08, 2024

Visual Studio Collector Service Denial of Service Vulnerability

insecure temporary file

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Visual Studio 2022 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe