ZDI-CAN-18380: ZDI-23-1466: Microsoft Visual Studio FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2022-35825.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18380?
The severity of ZDI-CAN-18380 is classified as important due to its potential for remote sensitive information disclosure.
How do I fix ZDI-CAN-18380?
To mitigate ZDI-CAN-18380, users should apply the latest security updates provided by Microsoft for Visual Studio.
Who is affected by ZDI-CAN-18380?
ZDI-CAN-18380 affects installations of Microsoft Visual Studio that have not been updated to the latest security patches.
What type of attack does ZDI-CAN-18380 involve?
ZDI-CAN-18380 involves a remote attack that requires user interaction through visiting a malicious page or opening a malicious file.
What can attackers gain from exploiting ZDI-CAN-18380?
Attackers exploiting ZDI-CAN-18380 may gain access to sensitive information from affected installations of Microsoft Visual Studio.