Access Control Weakness in Visual Studio by Microsoft
CVE-2025-32703

5.5MEDIUM

What is CVE-2025-32703?

An access control weakness in Visual Studio permits authorized attackers to gain unauthorized access to sensitive information locally. This vulnerability arises from insufficient granularity in the access control mechanisms implemented within the software, potentially exposing critical data elements to users who should not have visibility into them. Users of affected versions are encouraged to apply the relevant security updates as outlined in the official advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Unknown 15.9.0 < 15.9.73

Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Unknown 16.11.0 < 16.11.47

Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.