ZeroHour

CVE-2026-71328

mass

Heap Buffer Overflow in Microsoft Visual Studio Allows Network Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-71328 is a heap-based buffer overflow (CWE-122) in Microsoft Visual Studio that an unauthorized attacker can trigger remotely to execute code. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates a network-reachable flaw requiring no authentication and of low attack complexity, but one that requires user interaction, suggesting the attacker must persuade a user to open or process crafted content such as a project or package. Successful exploitation would give the attacker code execution with the privileges of the user running Visual Studio, with high confidentiality, integrity, and availability impact. Developers and organizations running affected Visual Studio installations are exposed; the advisory is tagged to the NuGet ecosystem, but no specific affected version ranges are provided in the available data. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days.

What to do: Monitor Microsoft's advisory and apply the corresponding Visual Studio security update via the Visual Studio Installer as soon as it is available, checking Help > About in the IDE against Microsoft's release notes for affected version ranges. Until patched, treat untrusted solutions, projects, and NuGet packages as risky and avoid opening them on development workstations. Because no public PoC or in-the-wild exploitation is known, patching during the regular update cycle is reasonable, but prioritize developer-facing and CI machines that handle third-party content.

Affected
Microsoft Visual Studio
Estimated exposure
mass≈ millions of Visual Studio installations worldwide (upper bound; actual exposure limited to affected versions) — Visual Studio is Microsoft's flagship Windows IDE with a user base in the millions, so the plausible exposure ceiling is millions of developer workstations, narrowed by unspecified affected version ranges and the user-interaction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
visual studio 2022, visual studio 2026, .net
Ecosystems
nuget
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
GHSA
GHSA-63gh-g2x5-x69v (high)

In the news

No ingested article mentions this CVE yet.