Visual Studio 2022

Vendor:

First CVE: Sep 15, 2020 · Active for 5 years

129
Total CVEs
More Total CVEs than 99% of tracked products
18.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Visual Studio 2022 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2020
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Visual Studio 2022129 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local52 (40.3%)
Network77 (59.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low111 (86.0%)
High18 (14.0%)
Unknown0 (0.0%)
User Interaction
None64 (49.6%)
Unknown0 (0.0%)
Required65 (50.4%)
Privileges Required
Low44 (34.1%)
High1 (0.8%)
None84 (65.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (129 CVEs).

129 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
Oct 14, 20259.982NOYES
.NET and Visual Studio Denial of Service Vulnerability
Aug 8, 20237.570YESNO
Microsoft QUIC Denial of Service Vulnerability
Oct 10, 20237.560NONO
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Jul 14, 20268.838NONO
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Jul 14, 20268.838NONO
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Nov 14, 20239.837NONO
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Jul 14, 20268.236NONO
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Jul 14, 20267.534NONO
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Jul 14, 20267.534NONO

Exploit Exposure

Signals from CVEs in this product scope (129 CVEs).

CISA KEV
2 CVEs
1.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.6% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (129 CVEs).

Media Mentions

Signals from CVEs in this product scope (129 CVEs).

Top CNAs Publishing CVEs For Visual Studio 2022

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
17.417.81.1%00
17.337.72.3%00
17.278.31.8%00
17.147.33.5%00
17.0118.22.2%00