First published: Tue Mar 11 2025(Updated: )
<p>Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio 2019 | =16.11 | |
Microsoft Visual Studio 2017 | =15.9 | |
Visual Studio Community 2022 | =17.10 | |
Visual Studio Community 2022 | =17.12 | |
Visual Studio Community 2022 | =17.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24998 is considered a high-severity vulnerability due to its potential for allowing local privilege escalation.
To fix CVE-2025-24998, you should update to the latest version of Visual Studio that includes the security patch addressing this vulnerability.
CVE-2025-24998 affects Visual Studio 2019 versions up to 16.10, Visual Studio 2022, and Visual Studio 2017 version 15.9.
Authorized users of the affected versions of Visual Studio may be vulnerable to CVE-2025-24998, enabling them to elevate privileges locally.
CVE-2025-24998 is classified as an elevation of privilege vulnerability within Visual Studio.