CVE-2019-0546

Description

A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka Visual Studio Remote Code Execution Vulnerability. This affects Microsoft Visual Studio.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
27.62

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Visual Studio Information Disclosure Vulnerability for the information disclosure vulnerability in Visual Studio 2010 Service Pack 1 (KB4476698)Windows
Microsoft Visual Studio Information Disclosure Vulnerability for the information disclosure vulnerability in Visual Studio 2012 Update 5 (KB4476755)Windows
Multiple Vulnerabilities are affected in Microsoft Visual Studio Community 2017 15.9Windows
Multiple Vulnerabilities are affected in Microsoft Visual Studio Enterprise 2017 15.9Windows
Multiple Vulnerabilities are affected in Microsoft Visual Studio Professional 2017 15.9Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-26017Security update for the information disclosure vulnerability in Visual Studio 2010 Service Pack 1 (KB4476698)
PATCH-26016Security update for the information disclosure vulnerability in Visual Studio 2012 Update 5 (KB4476755)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234