Elevation of Privilege Vulnerability in Visual Studio Installer by Microsoft
CVE-2025-21206
7.3HIGH
Key Information:
Summary
The Visual Studio Installer is susceptible to an elevation of privilege vulnerability that can be exploited by an attacker to gain elevated permissions on affected systems. This vulnerability may allow a malicious actor to execute arbitrary code with elevated privileges, potentially compromising the integrity of the software environment. It is crucial for users to be aware of this vulnerability and apply the necessary updates to mitigate risk.
Affected Version(s)
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Unknown 15.9.0 < 15.9.70
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Unknown 16.11.0 < 16.11.44
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.11
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved