← Vulnerability feed

Vulnerability record · CVE-2019-1350 · published 24 January 2020

CVE-2019-1350: Microsoft visual studio 2017 improper input validation vulnerability

Microsoft · Visual Studio 2017

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

8.8 CVSS 3.1 High EPSS 26% · top 2.1% CWE-20 · Improper input validation
8.8CVSS 3.1 base score, v2 9.3
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-1350 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed9.8CVE-2026-47304Microsoft .net framework insufficient verification of data authenticity vulnerabilityImproper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.EPSS 0.29%8.8CVE-2025-49739Microsoft visual studio link following vulnerabilityImproper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.EPSS 0.80%8.8CVE-2025-21176Microsoft .net vulnerability.NET, .NET Framework, and Visual Studio Remote Code Execution VulnerabilityEPSS 2.3%8.8CVE-2025-21178Microsoft visual studio 2017 heap-based buffer overflow vulnerabilityVisual Studio Remote Code Execution VulnerabilityEPSS 1.6%8.8CVE-2024-28936Microsoft odbc driver for sql server integer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.4%8.8CVE-2024-28937Microsoft odbc driver for sql server heap-based buffer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.3%8.8CVE-2024-28938Microsoft odbc driver for sql server out-of-bounds read vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2019-1350), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.