Improper Access Control in Visual Studio by Microsoft
CVE-2025-29804

7.3HIGH

Summary

An improper access control vulnerability in Visual Studio enables an authorized attacker to gain elevated privileges within the software, potentially compromising system integrity. This issue allows for local privilege escalation, which could be exploited to perform unauthorized actions or access sensitive information. Users are advised to apply security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.13

Microsoft Visual Studio 2022 version 17.12 Unknown 17.0 < 17.12.7

Microsoft Visual Studio 2022 version 17.13 Unknown 17.10 < 17.13.6

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.