Site icon API Security Blog

Security Updates for Microsoft Visual Studio Products (Feb 2023)

The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by multiple vulnerabilities:

– A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-21808, CVE-2023-21815, CVE-2023-23381)

– An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2023-21566)

– A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2023-21567)

Note that Nessus has not tested for this issue but has instead relied only on the application’s self-reported version number.Read More

Exit mobile version