Access Control Weakness in Visual Studio by Microsoft
CVE-2025-32703
5.5MEDIUM
Key Information:
What is CVE-2025-32703?
An access control weakness in Visual Studio permits authorized attackers to gain unauthorized access to sensitive information locally. This vulnerability arises from insufficient granularity in the access control mechanisms implemented within the software, potentially exposing critical data elements to users who should not have visibility into them. Users of affected versions are encouraged to apply the relevant security updates as outlined in the official advisory.
Affected Version(s)
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Unknown 15.9.0 < 15.9.73
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Unknown 16.11.0 < 16.11.47
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.14