Vulnerability record · CVE-2021-27068 · published 11 May 2021
CVE-2021-27068: Microsoft Visual Studio 2019 remote code execution flaw
Microsoft · Visual Studio 2019
CVE-2021-27068 is a remote code execution vulnerability in Microsoft Visual Studio 2019. The record gives only a one-line description and no root-cause detail, so the exact vulnerable component is unknown. A network-reachable RCE in a developer tool matters because it can compromise build and development environments.
Description
Visual Studio Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS, though exploitation is not confirmed in KEV and the record lacks root-cause detail.
What it is
CVE-2021-27068 is a remote code execution vulnerability in Microsoft Visual Studio 2019. The record gives only a one-line description and no root-cause detail, so the exact vulnerable component is unknown. A network-reachable RCE in a developer tool matters because it can compromise build and development environments.
Impact
An attacker who can reach the vulnerable component could execute code in the context of the Visual Studio process, potentially gaining the privileges of the developer or build account. The CVSS vector rates high confidentiality, integrity and availability impact.
Attack surface
The vector is network-based (AV:N) with low attack complexity and no user interaction (UI:N), but it requires low privileges (PR:L), so the attacker needs some prior access or an authenticated position rather than being fully unauthenticated. The description does not state which Visual Studio feature or protocol is reached.
Exploitation
CISA KEV does not list this CVE and no ransomware use is documented, but EPSS is high at roughly 0.54 (99th percentile), indicating elevated predicted exploitation activity. The only references are Microsoft's patch advisory, with no public exploit or PoC tags.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-27068 as the first action.
- Update Visual Studio 2019 to a supported, fully patched release and confirm the build is no longer affected.
- Restrict network exposure of developer workstations and build servers so untrusted hosts cannot reach Visual Studio services.
- Run Visual Studio and build processes under least-privilege accounts to limit the impact of code execution.
- Monitor Microsoft advisories for any follow-up guidance or revised affected-product details.
Detection
- Monitor for unexpected child processes spawned by devenv.exe or other Visual Studio processes.
- Alert on unusual network connections to or from developer workstations and build servers.
- Review Visual Studio and build-server logs for anomalous activity around the time of the patch window.
- Track endpoint telemetry for code execution or file writes in developer tooling directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27068 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27068 | PatchVendor Advisory |
Track CVE-2021-27068 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.