QID 92127

Date Published: 2024-03-13

QID 92127: Microsoft Visual Studio Security Update for March 2024

Microsoft has released March 2024 security updates for Visual Studio to fix multiple security vulnerabilities.

Affected Software:
Microsoft Visual Studio 2022 version 17.4
Microsoft Visual Studio 2022 version 17.8
Microsoft Visual Studio 2022 version 17.9
Microsoft Visual Studio 2022 version 17.6

QID Detection Logic: Authenticated : Windows
This QID detects vulnerable versions of Microsoft Visual Studio by checking the registry key "HKLM\SOFTWARE\Microsoft" and file "devenv.exe" to check the version of the Visual Studio.

Successful exploitation of this vulnerability can lead to Denial of Service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to CVE-2024-26190 and https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21392 for more information on the vulnerability and it's patch.

    CVEs related to QID 92127

    Software Advisories
    Advisory ID Software Component Link
    CVE-2024-21392 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21392
    CVE-2024-26190 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190