Improper neutralization of special elements used in a command (‘command injection’) in Visual Studio allows an authorized attacker to execute code over a network.

Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016