Improper Access Control in Visual Studio by Microsoft
CVE-2025-29804
7.3HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
An improper access control vulnerability in Visual Studio enables an authorized attacker to gain elevated privileges within the software, potentially compromising system integrity. This issue allows for local privilege escalation, which could be exploited to perform unauthorized actions or access sensitive information. Users are advised to apply security patches to mitigate risks associated with this vulnerability.
Affected Version(s)
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.13
Microsoft Visual Studio 2022 version 17.12 Unknown 17.0 < 17.12.7
Microsoft Visual Studio 2022 version 17.13 Unknown 17.10 < 17.13.6
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved