Command Injection Flaw in Visual Studio by Microsoft
CVE-2025-32702
7.8HIGH
Key Information:
What is CVE-2025-32702?
A vulnerability in Visual Studio has been identified where improper handling of special elements can lead to command injection. This flaw allows unauthorized attackers to execute code locally on the affected system, potentially leading to significant security risks. Users of Visual Studio versions 2019 and 2022 are advised to mitigate the risks by applying the necessary updates and practicing caution in executing untrusted commands.
Affected Version(s)
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Unknown 16.11.0 < 16.11.47
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.14
Microsoft Visual Studio 2022 version 17.12 Unknown 17.0 < 17.12.8