Microsoft Visual Studio Remote Code Execution Vulnerability
CVE-2022-35777 Published on August 9, 2022
Visual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2022-35777 has been classified to as a Code Injection vulnerability or weakness.
Products Associated with CVE-2022-35777
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8):- Version 15.9.0 and below 15.9.50 is affected.
- Version 15.0.0 and below 16.9.24 is affected.
- Version 16.11.0 and below 16.11.18 is affected.
- Version 17.0.0 and below 17.0.13 is affected.
- Version 11.0.0 and below 11.0.61252.0 is affected.
- Version 12.0.0 and below 12.0.40699.0 is affected.
- Version 14.0.0 and below 14.0.27552.0 is affected.
- Version 17.2.0 and below 17.2.7 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.