Visual Studio

Vendor:

First CVE: Feb 18, 2000 · Active for 26 years

57
Total CVEs
More Total CVEs than 98% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Visual Studio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2000
26 years ago
Most Recent CVE
Jul 8, 2025
381 days ago

CVE Severity & Scoring

Visual Studio57 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local27 (47.4%)
Network11 (19.3%)
Unknown19 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (64.9%)
High1 (1.8%)
Unknown19 (33.3%)
User Interaction
None21 (36.8%)
Unknown19 (33.3%)
Required17 (29.8%)
Privileges Required
Low20 (35.1%)
High0 (0.0%)
None18 (31.6%)
Unknown19 (33.3%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6
Aug 18, 20089.372NOYES
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows
Jul 29, 20098.845NONO
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP
Jul 29, 20098.844NONO
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5
Sep 14, 20076.842NOYES
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remot
Jul 11, 20187.841NONO
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0
Aug 31, 20067.539NOYES
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not pro
Jul 29, 20096.536NONO
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002
Oct 14, 20099.335NONO
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Pr
Oct 14, 20099.335NONO
Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web
Aug 10, 20114.334NOYES

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
12.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Visual Studio

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.0.0.978216.831.0%01
6.096.322.5%06
201714.36.0%00
2015317.62.5%00
201397.76.6%00
2012107.56.7%00
201086.410.0%00
2008138.524.5%00
200577.026.2%01
200327.824.4%00
200216.810.9%00