CVE-2025-29804 describes an improper access control vulnerability in Microsoft Visual Studio 2022, allowing an authorized local attacker to elevate privileges. With a CVSS score of 7.3 (HIGH), exploitation requires low attack complexity and user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered some community discussion and media coverage, indicating a level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.8.0, < 17.8.20CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, < 17.10.13CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.12.0, < 17.12.7CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.13.0, < 17.13.6CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.