CVE-2026-71328
massHeap Buffer Overflow in Microsoft Visual Studio Allows Network Code Execution
CVE-2026-71328 is a heap-based buffer overflow (CWE-122) in Microsoft Visual Studio that an unauthorized attacker can trigger remotely to execute code. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates a network-reachable flaw requiring no authentication and of low attack complexity, but one that requires user interaction, suggesting the attacker must persuade a user to open or process crafted content such as a project or package. Successful exploitation would give the attacker code execution with the privileges of the user running Visual Studio, with high confidentiality, integrity, and availability impact. Developers and organizations running affected Visual Studio installations are exposed; the advisory is tagged to the NuGet ecosystem, but no specific affected version ranges are provided in the available data. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days.
What to do: Monitor Microsoft's advisory and apply the corresponding Visual Studio security update via the Visual Studio Installer as soon as it is available, checking Help > About in the IDE against Microsoft's release notes for affected version ranges. Until patched, treat untrusted solutions, projects, and NuGet packages as risky and avoid opening them on development workstations. Because no public PoC or in-the-wild exploitation is known, patching during the regular update cycle is reasonable, but prioritize developer-facing and CI machines that handle third-party content.
| Microsoft Visual Studio | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- visual studio 2022, visual studio 2026, .net
- Ecosystems
- nuget
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- GHSA
- GHSA-63gh-g2x5-x69v (high)
In the news0 stories
No ingested article mentions this CVE yet.