CVE Vulnerabilities

CVE-2018-1037

Use of Uninitialized Resource

Published: Apr 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka Microsoft Visual Studio Information Disclosure Vulnerability. This affects Microsoft Visual Studio.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
Visual_studioMicrosoft2010-sp1 (including)2010-sp1 (including)
Visual_studioMicrosoft2012-update5 (including)2012-update5 (including)
Visual_studioMicrosoft2013-update5 (including)2013-update5 (including)
Visual_studioMicrosoft2015-update3 (including)2015-update3 (including)
Visual_studioMicrosoft2017 (including)2017 (including)
Visual_studio_2017Microsoft15.6.6 (including)15.6.6 (including)
Visual_studio_2017Microsoft15.7 (including)15.7 (including)

Potential Mitigations

References