.NET and Visual Studio Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in .NET and Microsoft Visual Studio 2022. This issue arises from an untrusted search path, which allows an unauthorized attacker to execute code over a network. The vulnerability is present in .NET 9.0 and 8.0, as well as in Visual Studio 2022 versions 17.8, 17.10, 17.12, and 17.14.

Impact

Exploitation of this vulnerability allows for remote code execution.

Remediation

Users can apply the security update available through the Microsoft Visual Studio update channel. For .NET, the security update can be downloaded from the .NET download page for the respective version.

Added: Jun 13, 2025, 2:17 AM
Updated: Jun 13, 2025, 2:17 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.