9.3
CVSSv2

CVE-2018-8172

Published: 11/07/2018 Updated: 21/11/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft visual studio 2010

microsoft visual studio 2015

microsoft visual studio 2017 15.7.5

microsoft visual studio 2017 -

microsoft expression blend 3

microsoft expression blend 2

microsoft visual studio 2012

microsoft visual studio 2013

microsoft expression blend 4

Github Repositories

Microsoft Visual Studio CVE-2018-8172 Remote Code Execution Vulnerability

CVE-2018-8172 Microsoft Visual Studio CVE-2018-8172 Remote Code Execution Vulnerability darkcertcom/2018/08/microsoft-visual-studio-remote-code-execution-cve-2018-8172/ twittercom/SyFi2k

Recent Articles

Intel, Microsoft, Adobe release a swarm of bug fixes to ruin your week
The Register • Shaun Nichols in San Francisco • 11 Jul 2018

Massive patch dump with 112 fixes... and that's just for the Photoshop giant

IT admins face a busy week ahead as Microsoft, Intel, and Adobe have issued bundles of scheduled security fixes addressing more than 150 CVE-listed vulnerabilities. For Redmond, the July Patch Tuesday will bring fixes for 53 individual bugs, 25 of those allowing for remote code execution attacks. This includes the usual array of Edge and Internet Explorer memory corruption flaws that could allow an attacker to place exploits within a web page and use them to take over a system with the current u...