Elevation of Privilege Vulnerability in Visual Studio by Microsoft
CVE-2025-29813
10CRITICAL
What is CVE-2025-29813?
An elevation of privilege vulnerability in Visual Studio can be exploited by attackers to gain extended access to a project. This occurs when the application inadequately manages pipeline job tokens, enabling an attacker with existing project access to replace a short-term token with a long-term one. The vulnerability is mitigated in the latest update, which enhances the handling of these tokens to bolster security.
Affected Version(s)
Azure DevOps Unknown