A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
https://github.com/SyFi/CVE-2018-8172
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8172
https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-19842