Elevation of Privilege in Visual Studio by Microsoft
CVE-2025-25003

7.3HIGH

Summary

An uncontrolled search path element in Visual Studio enables an authorized attacker to exploit the system and gain elevated privileges. This vulnerability could lead to unauthorized actions within the affected product, compromising system integrity and security. The affected versions may not have adequate validation of user input when processing search paths, potentially allowing attackers to manipulate executable paths.

Affected Version(s)

Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Unknown 16.11.0 < 16.11.45

Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.12

Microsoft Visual Studio 2022 version 17.12 Unknown 17.0 < 17.12.6

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.