| CVE ID | |
| CVSS SCORE | 5.3, AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H | 
| AFFECTED VENDORS | 
                            
                            
                            Microsoft | 
                    
| AFFECTED PRODUCTS | 
                            
                            
                            Visual Studio | 
                    
| VULNERABILITY DETAILS | 
                             This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Visual Studio. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Visual Studio installer. By creating a symbolic link, an attacker can abuse the installer to write a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.  | 
                    
| ADDITIONAL DETAILS | 
                            
                            
                            
                             This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 120 day deadline. 07/07/21 – ZDI reported the vulnerabilities to the vendor  -- Mitigation:  | 
                    
| DISCLOSURE TIMELINE | 
                            
  | 
                    
| CREDIT | Michael DePlante (@izobashi) of Trend Micro's Zero Day Initiative |