QID 92052

Date Published: 2023-08-09

QID 92052: Microsoft Visual Studio Security Updates for August 2023

Microsoft has released security Updates for Visual Studio which resolve Security Feature Bypass and Escalation of Privileges Vulnerabilities.

Affected Software:
Microsoft Visual Studio 2022 version 17.6
Microsoft Visual Studio 2022 version 17.4
Microsoft Visual Studio 2022 version 17.2
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)

QID Detection Logic: Authenticated : Windows
This QID detects vulnerable versions of Microsoft Visual Studio by checking the registry key "HKLM\SOFTWARE\Microsoft" and file "evenv.exe" to check the version of the Visual Studio.

An unauthenticated attacker could bypass validation as a trusted source through a crafted certificate that could mislead a user to believing the file they are installing is legitimate.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 8.7 severity.
  • Solution
    Customers are advised to refer to CVE-2023-36897,CVE-2023-35391,CVE-2023-38178,CVE-2023-38180,CVE-2023-35390 for more information on these vulnerabilities and their patches.
    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-35390 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35390
    CVE-2023-35391 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35391
    CVE-2023-36897 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36897
    CVE-2023-38178 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-38178
    CVE-2023-38180 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-38180