CVE-2025-32702 is a command injection vulnerability in Microsoft Visual Studio 2019 and 2022, allowing an unauthorized attacker to execute code locally. With a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and no prerequisites (PR:N), leading to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation (KEV: No) and no public exploit code available (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0, < 16.11.47CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
>= 17.8.0, < 17.8.21CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, < 17.10.14CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.12.0, < 17.12.8CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.13.0, < 17.13.7CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.