CVE-2024-20656 is a high-severity Elevation of Privilege vulnerability affecting multiple versions of Microsoft Visual Studio, including 2017, 2019, and 2022. With a CVSS score of 7.8, this flaw allows a local attacker with low privileges to execute arbitrary code with elevated permissions, leading to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild (KEV), the vulnerability has garnered significant community discussion, with one public proof-of-concept mentioned on Reddit. No Metasploit, Nuclei, or ExploitDB modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio:2015:update3:*:*:*:*:*:* | ||
>= 15.0, < 15.9.59CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.11.33CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
>= 17.2, < 17.2.23CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.4, < 17.4.15CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.