Impact
Heap-based buffer overflow in Visual Studio exposes a remote code execution vector. An unauthorized attacker can craft data and send it over a network to trigger memory corruption and arbitrary code execution on the target system. The impact is that the attacker may gain full administrative control of the affected host, enabling tampering with data, installation of malware, or denial of service.
Affected Systems
Affected vendors include Microsoft .NET 10.0, 11.0, 8.0, 9.0 and several .NET Framework releases such as 3.5, 4.6.2 through 4.8.1. The vulnerability also impacts Microsoft Visual Studio 2022 version 17.14 and the upcoming Visual Studio 2026 version 18.9. System administrators should verify that any of these products are present on their infrastructure and that the versions are unpatched.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and while the EPSS score is not available, the lack of exploitation data does not diminish the risk of a remote attack. The vulnerability is not yet listed in CISA’s KEV catalog, but the potential for unrestricted code execution warrants immediate remediation. Therefore, organizations should treat this as an urgent risk if the affected software is present in a production environment.
OpenCVE Enrichment
Github GHSA