Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-29803

Опубликовано: 08 апр. 2025
Источник: msrc
CVSS3: 7.3
EPSS Низкий

Описание

Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker who successfully exploited this vulnerability could gain the privileges of the authenticated user.

According to the CVSS metric, the attack vector is local (AV:L), privileges are low (PR:L), and user interaction is required (UI:R). What is the target context of the remote code execution?

This attack requires an authenticated attacker to place a specially crafted .dll file in a local network location. When a victim runs this file, it loads the malicious DLL.

Обновления

ПродуктСтатьяОбновление
Visual Studio Tools for Applications (VSTA) 2019
Visual Studio Tools for Applications (VSTA) 2022
SQL Server Management Studio 20.2
VSTA 2022 SDK
VSTA 2019 SDK

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 23%
0.00073
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
github
5 месяцев назад

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
fstec
5 месяцев назад

Уязвимость набора инструментов для настройки приложений Microsoft Visual Studio Tools for Applications (VSTA), связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 23%
0.00073
Низкий

7.3 High

CVSS3