QID 91873

Date Published: 2022-03-09

QID 91873: Microsoft Visual Studio Security Update for March 2022

Microsoft has released security Updates for Visual Studio which resolves Remote Code Execution and Denial of Service vulnerability.
Affected Software:
Microsoft Visual Studio 2019 version 16.7 (includes 16.0 - 16.6)
Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Microsoft Visual Studio 2017 Version 17.0

QID Detection Logic: Authenticated

This QID detects vulnerable versions of Microsoft Visual Studio by checking the file version of the Visual Studio.

Prone to Remote Code Execution and Denial of Service Vulnerability

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to CVE-2022-24464, CVE-2020-8927 and CVE-2022-24512 for more information pertaining to these vulnerabilities.

    CVEs related to QID 91873

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-8927 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2020-8927
    CVE-2022-24464 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24464
    VCE-2022-24512 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24512