CVE-2025-29803 is a high-severity privilege escalation vulnerability (CVSS 7.3) affecting Microsoft Visual Studio Tools for Applications and SQL Server Management Studio. It stems from an uncontrolled search path element (CWE-427), allowing an authorized local attacker to elevate privileges. While the vulnerability has a high potential impact (confidentiality, integrity, and availability), there is currently no public exploit code available, nor is it known to be actively exploited in the wild. Community discussion and media coverage are minimal, with only one article mentioning it as part of a larger Patch Tuesday release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.2.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_management_studio:*:*:*:*:*:*:*:* | ||
< 16.0.35907.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019:*:*:*:*:*:*:*:* | ||
< 16.0.35907.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019_sdk:*:*:*:*:*:*:*:* | ||
< 17.0.35906.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022:*:*:*:*:*:*:*:* | ||
< 17.0.35906.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.