High severity7.3NVD Advisory· Published Apr 12, 2025· Updated Jun 17, 2026
CVE-2025-29803
CVE-2025-29803
Description
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Affected products
11- cpe:2.3:a:microsoft:sql_server_management_studio:*:*:*:*:*:*:*:*Range: <20.2.1
- cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019:*:*:*:*:*:*:*:*Range: <16.0.35907.0
- cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019_sdk:*:*:*:*:*:*:*:*Range: <16.0.35907.0
- cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022:*:*:*:*:*:*:*:*Range: <17.0.35906.0
- cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022_sdk:*:*:*:*:*:*:*:*Range: <17.0.35906.0
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 17.0
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 20.0
- Microsoft/VSTA 2019 SDKv5Range: 16.0
- Microsoft/VSTA 2022 SDKv5Range: 17.0
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29803nvdVendor Advisory
News mentions
0No linked articles in our index yet.