QID 92119

QID 92119: Microsoft Visual Studio Multiple Vulnerabilities

Microsoft has released security Updates for Visual Studio which resolve Remote Code Execution and Denial of Service.

Affected Software:
Microsoft Visual Studio 2022 version 17.6
Microsoft Visual Studio 2022 version 17.7
Microsoft Visual Studio 2022 version 17.4
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
Microsoft Visual Studio 2015 Update 3 Microsoft Visual Studio 2015 Update 5 Microsoft Visual Studio 2022 version 17.2

QID Detection Logic: Authenticated : Windows
This QID detects vulnerable versions of Microsoft Visual Studio by checking the registry key "HKLM\SOFTWARE\Microsoft" and file "evenv.exe" to check the version of the Visual Studio.

Successful exploit may impact confidentiality, integrity and availability

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to CVE-2023-36792, CVE-2023-36793, CVE-2023-36794, CVE-2023-36796, CVE-2023-36799 for more information on these vulnerabilities and their patches.
    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-36792 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36792
    CVE-2023-36793 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36793
    CVE-2023-36794 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36794
    CVE-2023-36796 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36796
    CVE-2023-36799 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36799