ZDI-25-1057: (0Day) Microsoft Visual Studio VsDevCmd Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1057?
The severity of ZDI-25-1057 is high due to its capability to allow remote code execution.
How do I fix ZDI-25-1057?
To fix ZDI-25-1057, ensure you are running the latest version of Microsoft Visual Studio with all security updates applied.
What types of attacks are possible with ZDI-25-1057?
ZDI-25-1057 allows remote attackers to execute arbitrary code through malicious webpages or files.
Is user interaction required to exploit ZDI-25-1057?
Yes, user interaction is required to exploit ZDI-25-1057, as the victim must visit a malicious page or open a malicious file.
What products are affected by ZDI-25-1057?
ZDI-25-1057 affects installations of Microsoft Visual Studio.