QID 91932

Date Published: 2022-08-10

QID 91932: Microsoft Visual Studio Security Update for August 2022

Microsoft has released security Updates for Visual Studio which resolves Remote Code Execution Vulnerabilities.

Affected Software:
Microsoft Visual Studio 2012 Update 5
Microsoft Visual Studio 2013 Update 5
Microsoft Visual Studio 2015 Update 3
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Microsoft Visual Studio 2022 Version 17.0
and Microsoft Visual Studio 2022 version 17.2

QID Detection Logic: Authenticated
This QID detects vulnerable versions of Microsoft Visual Studio by checking the file version of the Visual Studio.

Vulnerable versions of Microsoft Visual Studio are prone to Remote Code Execution Vulnerabilities.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to refer to CVE-2022-35777, CVE-2022-35827, CVE-2022-35826, and CVE-2022-35825 for more information pertaining to these vulnerabilities.

    CVEs related to QID 91932

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-35777 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35777
    CVE-2022-35825 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35825
    CVE-2022-35826 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35826
    CVE-2022-35827 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35827