Visual Studio 2022
Vendor:
First CVE: Sep 15, 2020 · Active for 5 years
129
Total CVEs
More Total CVEs than 99% of tracked products
18.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Visual Studio 2022 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2020
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Visual Studio 2022129 CVEs
19%
77%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local52 (40.3%)
Network77 (59.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low111 (86.0%)
High18 (14.0%)
Unknown0 (0.0%)
User Interaction
None64 (49.6%)
Unknown0 (0.0%)
Required65 (50.4%)
Privileges Required
Low44 (34.1%)
High1 (0.8%)
None84 (65.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (129 CVEs).
129 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2025-55315CRITICAL Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | Oct 14, 2025 | 9.9 | 82 | NO | YES |
CVE-2023-38180HIGH .NET and Visual Studio Denial of Service Vulnerability | Aug 8, 2023 | 7.5 | 70 | YES | NO |
CVE-2023-38171HIGH Microsoft QUIC Denial of Service Vulnerability | Oct 10, 2023 | 7.5 | 60 | NO | NO |
CVE-2026-47303HIGH Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-47300HIGH Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 38 | NO | NO |
CVE-2023-36049CRITICAL .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Nov 14, 2023 | 9.8 | 37 | NO | NO |
CVE-2026-50528HIGH Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-50651HIGH Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | Jul 14, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-50524HIGH Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | Jul 14, 2026 | 7.5 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (129 CVEs).
CISA KEV
2 CVEs
1.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.6% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (129 CVEs).
Media Mentions
Signals from CVEs in this product scope (129 CVEs).
Top CNAs Publishing CVEs For Visual Studio 2022
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 17.4 | 1 | 7.8 | 1.1% | 0 | 0 |
| 17.3 | 3 | 7.7 | 2.3% | 0 | 0 |
| 17.2 | 7 | 8.3 | 1.8% | 0 | 0 |
| 17.1 | 4 | 7.3 | 3.5% | 0 | 0 |
| 17.0 | 11 | 8.2 | 2.2% | 0 | 0 |