ZeroHour

CVE-2026-69522

mass

Heap Buffer Overflow RCE in Microsoft Visual Studio

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69522 is a heap-based buffer overflow (CWE-122) in Microsoft Visual Studio that is reachable over a network without authentication. The CVSS vector requires user interaction (UI:R), indicating the flaw is triggered when a user handles attacker-influenced content, such as opening a crafted file or project in the IDE. Successful exploitation yields arbitrary code execution on the developer workstation with the privileges of the user running Visual Studio, with high impact to confidentiality, integrity, and availability. Any organization or developer running Visual Studio is potentially affected, though the available data does not specify which version ranges are vulnerable. As of this analysis there is no evidence of exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns a low 0.8% probability of exploitation within 30 days.

What to do: Apply Microsoft's Visual Studio security update referenced in the advisory as soon as possible, and consult the advisory for the exact affected and fixed version ranges. Until patched, have developers avoid opening untrusted projects, files, or packages from unknown sources, since exploitation requires user interaction. No public PoC or in-the-wild exploitation is currently known, but monitor Microsoft's advisory for updates.

Affected
Microsoft Visual Studio
Estimated exposure
masstens of millions of developer workstations (Visual Studio install base) — Visual Studio is Microsoft's flagship IDE with an install base commonly cited in the tens of millions of developers, so even a subset of installs exceeds the >1M-user threshold; exact affected versions are unknown, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Ecosystems
nuget
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
GHSA
GHSA-2j8r-3c22-8565 (high)

In the news

No ingested article mentions this CVE yet.