← Vulnerability feed

Vulnerability record · CVE-2021-36952 · published 15 September 2021

CVE-2021-36952: Microsoft Visual Studio Out-of-Bounds Write Remote Code Execution

Microsoft · Visual Studio 2017

CVE-2021-36952 is an out-of-bounds write (CWE-787) in Microsoft Visual Studio 2017 and 2019 that can lead to remote code execution. The vulnerability has a CVSS 3.1 base score of 7.8 (HIGH) and requires user interaction, meaning an attacker must convince a victim to open a crafted file or project. Because Visual Studio is a developer tool, a successful exploit could compromise a development workstation and potentially the code and credentials it handles.

7.8 CVSS 3.1 High EPSS 51% · top 1.1% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 6.8
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References
10 Aug 2026Last modified by NVD

Description

Visual Studio Remote Code Execution Vulnerability

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 7.8 and a very high EPSS percentile indicate significant risk, but the local vector and user interaction requirement reduce the likelihood of widespread, unattended exploitation.

What it is

CVE-2021-36952 is an out-of-bounds write (CWE-787) in Microsoft Visual Studio 2017 and 2019 that can lead to remote code execution. The vulnerability has a CVSS 3.1 base score of 7.8 (HIGH) and requires user interaction, meaning an attacker must convince a victim to open a crafted file or project. Because Visual Studio is a developer tool, a successful exploit could compromise a development workstation and potentially the code and credentials it handles.

Impact

An attacker who successfully exploits this flaw can execute arbitrary code in the context of the current user. Given the local vector and user interaction requirement, the practical impact is code execution on a developer's machine, which may expose source code, signing keys, and access to internal build systems.

Attack surface

The attack is local (AV:L) and requires user interaction (UI:R), so it is reached by getting a victim to open a malicious file, project, or other content in Visual Studio. No privileges are required (PR:N), but the attacker must deliver the crafted content to the user and persuade them to open it.

Exploitation

CVE-2021-36952 is not listed in CISA KEV and has no documented ransomware use. EPSS estimates a 30-day exploitation probability of 0.51178 (98.9th percentile), indicating a high likelihood of attempted exploitation, though the record does not confirm public exploit code or active attacks.

What to do

  • Apply the Microsoft security update for Visual Studio 2017 and 2019 referenced in the MSRC advisory as soon as possible.
  • Restrict opening of untrusted Visual Studio projects, solutions, and related files from email, downloads, or removable media.
  • Run Visual Studio with least privilege and avoid using administrator accounts for day-to-day development.
  • Enable attack surface reduction and endpoint protection rules that block Office and script-based delivery of malicious project files.
  • Monitor for and block known exploit delivery vectors such as archives containing Visual Studio project files from external sources.

Detection

  • Monitor process creation for devenv.exe spawning unexpected child processes such as cmd.exe, powershell.exe, or scripting hosts.
  • Alert on Visual Studio opening files from unusual locations such as temp directories, email attachment caches, or removable drives.
  • Review endpoint telemetry for out-of-bounds write crash patterns or abnormal memory corruption in Visual Studio processes.
  • Track exploitation attempts via EDR or Windows event logs for suspicious file opens followed by process injection or network connections from devenv.exe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-36952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed9.8CVE-2026-47304Microsoft .net framework insufficient verification of data authenticity vulnerabilityImproper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.EPSS 0.29%8.8CVE-2025-49739Microsoft visual studio link following vulnerabilityImproper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.EPSS 0.80%8.8CVE-2025-21176Microsoft .net vulnerability.NET, .NET Framework, and Visual Studio Remote Code Execution VulnerabilityEPSS 2.3%8.8CVE-2025-21178Microsoft visual studio 2017 heap-based buffer overflow vulnerabilityVisual Studio Remote Code Execution VulnerabilityEPSS 1.6%8.8CVE-2024-28936Microsoft odbc driver for sql server integer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.4%8.8CVE-2024-28937Microsoft odbc driver for sql server heap-based buffer overflow vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.3%8.8CVE-2024-28938Microsoft odbc driver for sql server out-of-bounds read vulnerabilityMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2021-36952), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.