CVE-2014-3802: Microsoft Debug Interface Access Software Development Kit
Medium severity, CVSS 6.8. EPSS: 10.9% chance of exploitation in the next 30 days.
msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDB file.
Affected products
- Microsoft Debug Interface Access Software Development Kit: affected versions not specified
- Microsoft Visual Studio: up to and including 2012; version 2002 only; version 2003 only; version 2005 only; version 2010 only
Published 2014-05-20. Last modified 2026-06-17.