CVE-2022-30184
CVE-2022-30184 is a medium-severity vulnerability in Microsoft Visual Studio 2022 with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-200.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- CVSS v2: 4.3
- EPSS exploit prediction: 6% (93rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-200
- Affected product: Microsoft Visual Studio 2022
- Published:
- Last modified:
Description
.NET and Visual Studio Information Disclosure Vulnerability
Frequently asked questions
- What is CVE-2022-30184?
- .NET and Visual Studio Information Disclosure Vulnerability
- How severe is CVE-2022-30184?
- CVE-2022-30184 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2022-30184 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 6% (93rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-30184?
- CVE-2022-30184 primarily affects Microsoft Visual Studio 2022. In total, 8 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-30184?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2022-30184 published?
- CVE-2022-30184 was published on 2022-06-15 and last updated on 2026-06-17.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30184
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DMP34G53EA2DBTBLFOAQCDZRRENE2EA2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWNH4AC3LFVX35MDRX5OBZDGD2AMH66K/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30184
Affected products (8)
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net:6.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_core:3.1:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:nuget:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2019:8.10:*:*:*:*:macos:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Visual Studio 2022
- CVE-2025-55315 — Critical (CVSS 9.9): Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized…
- CVE-2024-43498 — Critical (CVSS 9.8): .NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2024-0057 — Critical (CVSS 9.1): NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
- CVE-2026-71328 — High (CVSS 8.8): Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-69439 — High (CVSS 8.8): Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-47303 — High (CVSS 8.8): Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges…
All CVEs affecting Microsoft Visual Studio 2022 →
Other CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities
- CVE-2026-92960 — Critical (CVSS 10.0): vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing…
- CVE-2026-92947 — Critical (CVSS 10.0): vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by…
- CVE-2026-70478 — Critical (CVSS 10.0): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…
- CVE-2026-27604 — Critical (CVSS 10.0): FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version…
- CVE-2026-40965 — Critical (CVSS 10.0): Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a…
- CVE-2026-42826 — Critical (CVSS 10.0): Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose…
Browse all CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities →