Visual Studio Elevation of Privilege Vulnerability
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Visual_studio | Microsoft | 2015-update3 (including) | 2015-update3 (including) |
Visual_studio_2017 | Microsoft | 15.0 (including) | 15.9.59 (excluding) |
Visual_studio_2019 | Microsoft | 16.0 (including) | 16.11.33 (excluding) |
Visual_studio_2022 | Microsoft | 17.2 (including) | 17.2.23 (excluding) |
Visual_studio_2022 | Microsoft | 17.4 (including) | 17.4.15 (excluding) |
Visual_studio_2022 | Microsoft | 17.6 (including) | 17.6.11 (excluding) |