CVE Vulnerabilities

CVE-2018-1037

Use of Uninitialized Resource

Published: Apr 12, 2018 | Modified: Aug 12, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka Microsoft Visual Studio Information Disclosure Vulnerability. This affects Microsoft Visual Studio.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Visual_studio Microsoft 2010-sp1 (including) 2010-sp1 (including)
Visual_studio Microsoft 2012-update5 (including) 2012-update5 (including)
Visual_studio Microsoft 2013-update5 (including) 2013-update5 (including)
Visual_studio Microsoft 2015-update3 (including) 2015-update3 (including)
Visual_studio Microsoft 2017 (including) 2017 (including)
Visual_studio_2017 Microsoft 15.6.6 (including) 15.6.6 (including)
Visual_studio_2017 Microsoft 15.7 (including) 15.7 (including)

Potential Mitigations

References