QID 91815

Date Published: 2021-09-15

QID 91815: Microsoft Visual Studio Security Update for September 2021

Microsoft has released security Updates for Visual Studio which resolves Remote Code Execution and Elevation of Privilege vulnerability.
Affected Software:
Microsoft Visual Studio 2017 Version 15.9 (includes 15.0 - 15.8)
Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
Microsoft Visual Studio 2019 version 16.7 (includes 16.0 - 16.6)
Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)

QID Detection Logic: Authenticated

This QID detects vulnerable versions of Microsoft Visual Studio by checking the file version of the Visual Studio.

Prone to Remote Code Execution and Elevation of Privilege Vulnerability

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Customers are advised to refer to CVE-2021-26434 and CVE-2021-36952 for more information pertaining to these vulnerabilities.

    CVEs related to QID 91815

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-26434 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26434
    CVE-2021-36952 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36952