9.3

CVE-2018-8172

A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftExpression Blend Version2 Updatesp2
MicrosoftExpression Blend Version3 Updatesp1
MicrosoftExpression Blend Version4 Updatesp3
MicrosoftVisual Studio Version2010 Updatesp1
MicrosoftVisual Studio Version2012 Updateupdate_5
MicrosoftVisual Studio Version2013 Updateupdate_5
MicrosoftVisual Studio Version2015 Updateupdate3
MicrosoftVisual Studio 2017 Version15.7.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 24.61% 0.959
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C