Visual Studio 2017

Vendor:

First CVE: Apr 12, 2018 · Active for 8 years

92
Total CVEs
More Total CVEs than 99% of tracked products
11.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Visual Studio 2017 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2018
8 years ago
Most Recent CVE
Oct 14, 2025
283 days ago

CVE Severity & Scoring

Visual Studio 201792 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local63 (68.5%)
Network29 (31.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low88 (95.7%)
High4 (4.3%)
Unknown0 (0.0%)
User Interaction
None45 (48.9%)
Unknown0 (0.0%)
Required47 (51.1%)
Privileges Required
Low45 (48.9%)
High0 (0.0%)
None47 (51.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (92 CVEs).

92 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.
Jul 14, 20207.898YESYES
Visual Studio Remote Code Execution Vulnerability
Sep 15, 20217.854NONO
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is
Jan 24, 20208.846NONO
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is
Jan 24, 20208.841NONO
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remot
Jul 11, 20187.841NONO
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is
Jan 24, 20208.840NONO
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is
Jan 24, 20208.840NONO
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation
Aug 15, 20187.837NOYES
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully
Mar 5, 20198.834NONO
A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Studio Remote Code Execu
Jan 8, 20197.833NONO

Exploit Exposure

Signals from CVEs in this product scope (92 CVEs).

CISA KEV
1 CVE
1.1% of CVEs· 96th percentile
Metasploit
1 CVE
1.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (92 CVEs).

Media Mentions

Signals from CVEs in this product scope (92 CVEs).

Top CNAs Publishing CVEs For Visual Studio 2017

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
16.118.810.0%00
16.018.810.0%00
15.9187.35.0%00
15.827.83.7%01
15.7.527.816.1%00
15.714.36.0%00
15.6.614.36.0%00
15.027.80.9%00