CVE-2018-8172
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 31.02% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/expression blend · microsoft/visual studio · microsoft/visual studio 2017
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/104616Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041253Broken Link, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8172Patch, Vendor Advisory
- http://www.securityfocus.com/bid/104616Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041253Broken Link, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8172Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.