ZDI-23-1466: Microsoft Visual Studio FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2022-35825.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1466?
The severity of ZDI-23-1466 is critical due to its potential for remote information disclosure.
How do I fix ZDI-23-1466?
To fix ZDI-23-1466, users should apply the latest security updates provided by Microsoft for Visual Studio.
Who is affected by ZDI-23-1466?
ZDI-23-1466 affects installations of Microsoft Visual Studio that are not updated with the latest security patches.
What type of attack does ZDI-23-1466 involve?
ZDI-23-1466 involves a remote attack that requires user interaction with a malicious webpage or file.
Can ZDI-23-1466 be exploited without user interaction?
No, ZDI-23-1466 cannot be exploited without user interaction.