CVE-2023-23381: Visual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.27555.0Patch KB5025792 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.2.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.9.52 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.40700.0Patch KB5026610 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.24 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.19
Event History
Frequently Asked Questions
What is CVE-2023-23381?
CVE-2023-23381 is a remote code execution vulnerability in Visual Studio.
How severe is CVE-2023-23381?
CVE-2023-23381 has a severity rating of 7.8 out of 10, which is considered critical.
Which versions of Visual Studio are affected by CVE-2023-23381?
CVE-2023-23381 affects Visual Studio 2017 (includes 15.0 - 15.8), Visual Studio 2022 (versions 17.4, 17.2, and 17.0), Visual Studio 2019 (includes 16.0 - 16.10), Visual Studio 2015, and Visual Studio 2013.
How do I fix CVE-2023-23381 in Visual Studio 2017?
To fix CVE-2023-23381 in Visual Studio 2017, update to version 15.9 or later.
Where can I find the patch for CVE-2023-23381 in Visual Studio 2022?
You can find the patch for CVE-2023-23381 in Visual Studio 2022 version 17.4 at https://my.visualstudio.com/Downloads?q=Visual%20Studio%202022%20version%2017.4.