CVE-2023-28299 is a spoofing vulnerability affecting Microsoft Visual Studio 2017, 2019, and 2022. Rated as medium severity (CVSS 5.5), it requires local access and low privileges, but does not involve user interaction, potentially leading to high integrity impact without affecting confidentiality or availability. There is no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this vulnerability are minimal, with only one article mentioning it as part of Microsoft's April 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.0, < 15.9.54CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.11.26CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.0.21CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.2.0, < 17.2.15CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:* | ||
>= 17.4.0, < 17.4.7CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.