ZDI-CAN-18378: ZDI-23-1465: Microsoft Visual Studio FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2022-35825.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18378?
The severity of ZDI-CAN-18378 is assessed to be moderate due to its potential to disclose sensitive information.
How do I fix ZDI-CAN-18378?
To fix ZDI-CAN-18378, users should ensure they are using the latest version of Microsoft Visual Studio and apply any relevant security updates.
What are the risks associated with ZDI-CAN-18378?
The risks associated with ZDI-CAN-18378 include the unauthorized disclosure of sensitive information if a user interacts with a malicious page or file.
Who is affected by ZDI-CAN-18378?
Users of Microsoft Visual Studio are affected by ZDI-CAN-18378.
Is user interaction required to exploit ZDI-CAN-18378?
Yes, user interaction is required to exploit ZDI-CAN-18378, as the target must visit a malicious page or open a malicious file.