ZDI-23-1460: Microsoft Visual Studio FBX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2022-35825.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1460?
The severity of ZDI-23-1460 is classified as critical due to the potential for remote code execution.
How do I fix ZDI-23-1460?
To fix ZDI-23-1460, update Microsoft Visual Studio to the latest version that addresses this vulnerability.
What are the exploitation requirements for ZDI-23-1460?
Exploitation of ZDI-23-1460 requires user interaction, either by visiting a malicious page or opening a malicious file.
What is the impact of ZDI-23-1460?
The impact of ZDI-23-1460 allows remote attackers to execute arbitrary code on affected installations of Microsoft Visual Studio.
Which software versions are affected by ZDI-23-1460?
ZDI-23-1460 affects affected installations of Microsoft Visual Studio, although specific versions were not listed.