Vulnerability record · CVE-2021-36952 · published 15 September 2021
CVE-2021-36952: Microsoft Visual Studio Out-of-Bounds Write Remote Code Execution
Microsoft · Visual Studio 2017
CVE-2021-36952 is an out-of-bounds write (CWE-787) in Microsoft Visual Studio 2017 and 2019 that can lead to remote code execution. The vulnerability has a CVSS 3.1 base score of 7.8 (HIGH) and requires user interaction, meaning an attacker must convince a victim to open a crafted file or project. Because Visual Studio is a developer tool, a successful exploit could compromise a development workstation and potentially the code and credentials it handles.
Description
Visual Studio Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 and a very high EPSS percentile indicate significant risk, but the local vector and user interaction requirement reduce the likelihood of widespread, unattended exploitation.
What it is
CVE-2021-36952 is an out-of-bounds write (CWE-787) in Microsoft Visual Studio 2017 and 2019 that can lead to remote code execution. The vulnerability has a CVSS 3.1 base score of 7.8 (HIGH) and requires user interaction, meaning an attacker must convince a victim to open a crafted file or project. Because Visual Studio is a developer tool, a successful exploit could compromise a development workstation and potentially the code and credentials it handles.
Impact
An attacker who successfully exploits this flaw can execute arbitrary code in the context of the current user. Given the local vector and user interaction requirement, the practical impact is code execution on a developer's machine, which may expose source code, signing keys, and access to internal build systems.
Attack surface
The attack is local (AV:L) and requires user interaction (UI:R), so it is reached by getting a victim to open a malicious file, project, or other content in Visual Studio. No privileges are required (PR:N), but the attacker must deliver the crafted content to the user and persuade them to open it.
Exploitation
CVE-2021-36952 is not listed in CISA KEV and has no documented ransomware use. EPSS estimates a 30-day exploitation probability of 0.51178 (98.9th percentile), indicating a high likelihood of attempted exploitation, though the record does not confirm public exploit code or active attacks.
What to do
- Apply the Microsoft security update for Visual Studio 2017 and 2019 referenced in the MSRC advisory as soon as possible.
- Restrict opening of untrusted Visual Studio projects, solutions, and related files from email, downloads, or removable media.
- Run Visual Studio with least privilege and avoid using administrator accounts for day-to-day development.
- Enable attack surface reduction and endpoint protection rules that block Office and script-based delivery of malicious project files.
- Monitor for and block known exploit delivery vectors such as archives containing Visual Studio project files from external sources.
Detection
- Monitor process creation for devenv.exe spawning unexpected child processes such as cmd.exe, powershell.exe, or scripting hosts.
- Alert on Visual Studio opening files from unusual locations such as temp directories, email attachment caches, or removable drives.
- Review endpoint telemetry for out-of-bounds write crash patterns or abnormal memory corruption in Visual Studio processes.
- Track exploitation attempts via EDR or Windows event logs for suspicious file opens followed by process injection or network connections from devenv.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36952 | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36952 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1076/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-36952 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36952), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.