Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft sql Server Management Studio Microsoft visual Studio Tools For Applications 2019 Microsoft visual Studio Tools For Applications 2019 Sdk Microsoft visual Studio Tools For Applications 2022 Microsoft visual Studio Tools For Applications 2022 Sdk |
|
CPEs | cpe:2.3:a:microsoft:sql_server_management_studio:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019_sdk:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022_sdk:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Microsoft
Microsoft sql Server Management Studio Microsoft visual Studio Tools For Applications 2019 Microsoft visual Studio Tools For Applications 2019 Sdk Microsoft visual Studio Tools For Applications 2022 Microsoft visual Studio Tools For Applications 2022 Sdk |
Mon, 14 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 12 Apr 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | |
Title | Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-06-04T17:53:26.365Z
Reserved: 2025-03-11T18:19:40.248Z
Link: CVE-2025-29803

Updated: 2025-04-14T16:36:44.882Z

Status : Analyzed
Published: 2025-04-12T02:15:20.990
Modified: 2025-07-10T14:53:39.120
Link: CVE-2025-29803

No data.