← Vulnerability feed

Vulnerability record · CVE-2021-27068 · published 11 May 2021

CVE-2021-27068: Microsoft Visual Studio 2019 remote code execution flaw

Microsoft · Visual Studio 2019

CVE-2021-27068 is a remote code execution vulnerability in Microsoft Visual Studio 2019. The record gives only a one-line description and no root-cause detail, so the exact vulnerable component is unknown. A network-reachable RCE in a developer tool matters because it can compromise build and development environments.

8.8 CVSS 3.1 High EPSS 54% · top 1.0%
8.8CVSS 3.1 base score, v2 6.5
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Visual Studio Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: low.

high priorityCVSS 8.8 with network reachability and high EPSS, though exploitation is not confirmed in KEV and the record lacks root-cause detail.

What it is

CVE-2021-27068 is a remote code execution vulnerability in Microsoft Visual Studio 2019. The record gives only a one-line description and no root-cause detail, so the exact vulnerable component is unknown. A network-reachable RCE in a developer tool matters because it can compromise build and development environments.

Impact

An attacker who can reach the vulnerable component could execute code in the context of the Visual Studio process, potentially gaining the privileges of the developer or build account. The CVSS vector rates high confidentiality, integrity and availability impact.

Attack surface

The vector is network-based (AV:N) with low attack complexity and no user interaction (UI:N), but it requires low privileges (PR:L), so the attacker needs some prior access or an authenticated position rather than being fully unauthenticated. The description does not state which Visual Studio feature or protocol is reached.

Exploitation

CISA KEV does not list this CVE and no ransomware use is documented, but EPSS is high at roughly 0.54 (99th percentile), indicating elevated predicted exploitation activity. The only references are Microsoft's patch advisory, with no public exploit or PoC tags.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-27068 as the first action.
  • Update Visual Studio 2019 to a supported, fully patched release and confirm the build is no longer affected.
  • Restrict network exposure of developer workstations and build servers so untrusted hosts cannot reach Visual Studio services.
  • Run Visual Studio and build processes under least-privilege accounts to limit the impact of code execution.
  • Monitor Microsoft advisories for any follow-up guidance or revised affected-product details.

Detection

  • Monitor for unexpected child processes spawned by devenv.exe or other Visual Studio processes.
  • Alert on unusual network connections to or from developer workstations and build servers.
  • Review Visual Studio and build-server logs for anomalous activity around the time of the patch window.
  • Track endpoint telemetry for code execution or file writes in developer tooling directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27068 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed9.8CVE-2026-47304Microsoft .net framework insufficient verification of data authenticity vulnerabilityImproper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.EPSS 0.29%8.8CVE-2025-49739Microsoft visual studio link following vulnerabilityImproper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.EPSS 0.80%8.8CVE-2025-21178Microsoft visual studio 2017 heap-based buffer overflow vulnerabilityVisual Studio Remote Code Execution VulnerabilityEPSS 1.6%8.8CVE-2024-28936Microsoft odbc driver for sql server integer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.4%8.8CVE-2024-28937Microsoft odbc driver for sql server heap-based buffer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.3%8.8CVE-2024-28938Microsoft odbc driver for sql server out-of-bounds read vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.3%8.8CVE-2024-28931Microsoft odbc driver for sql server integer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2021-27068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.