CVE-2019-0809 is a remote code execution vulnerability affecting Microsoft Visual Studio 2017. The flaw stems from improper input validation in the Visual Studio C++ Redistributable Installer, allowing it to load malicious dynamic link library (DLL) files. With a CVSS score of 7.8 (High), this vulnerability requires local access and user interaction (UI:R) but can lead to high impact on confidentiality, integrity, and availability. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB: None) and it is not listed in CISA's KEV catalog, there has been some community discussion and media coverage surrounding its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.9CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.