Impact
A heap-based buffer overflow is present in Microsoft Visual Studio 2026 that allows an unauthorized attacker to execute code remotely. The flaw occurs when the application processes network input, leading to uncontrolled memory writes that can be leveraged to run arbitrary code with the privileges of the Visual Studio process.
Affected Systems
Microsoft Visual Studio 2026, version 18.9, is affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating a high severity of exploitation. The EPSS score is not available, so the current exploitation probability cannot be quantified. It is not listed in CISA’s KEV catalog. The likely attack vector is through a network connection to a vulnerable Visual Studio instance, allowing an attacker to trigger the overflow and execute arbitrary code.
OpenCVE Enrichment