CVE-2025-29803: Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Other sources
Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.35907.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.35906.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20.2.37.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29803?
CVE-2025-29803 has a high severity as it allows an authorized attacker to elevate privileges locally.
How do I fix CVE-2025-29803?
To fix CVE-2025-29803, update to the latest patched version of the affected software.
Which products are affected by CVE-2025-29803?
CVE-2025-29803 affects Microsoft Visual Studio Tools for Applications and SQL Server Management Studio.
Can I still use my affected software while CVE-2025-29803 is unresolved?
Using your affected software while CVE-2025-29803 is unresolved can pose security risks, as it may allow unauthorized privilege escalation.
Is there a patch available for CVE-2025-29803?
Yes, Microsoft has released patches to address CVE-2025-29803 for the affected software products.