ZDI-23-1464: Microsoft Visual Studio FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2022-35825.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1464?
ZDI-23-1464 is considered a medium severity vulnerability due to the requirement for user interaction to exploit it.
How do I fix ZDI-23-1464?
To resolve ZDI-23-1464, users should ensure their Microsoft Visual Studio installations are updated to the latest version provided by Microsoft.
Who is affected by ZDI-23-1464?
ZDI-23-1464 affects installations of Microsoft Visual Studio across various versions.
What type of information can be disclosed by ZDI-23-1464?
ZDI-23-1464 allows remote attackers to disclose potentially sensitive information from affected Microsoft Visual Studio installations.
Is user interaction required to exploit ZDI-23-1464?
Yes, user interaction is necessary as the target must visit a malicious page or open a malicious file for the exploit to succeed.