CVE-2025-32702: Visual Studio Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
Other sources
Visual Studio Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32702?
CVE-2025-32702 has a high severity rating due to its potential for allowing unauthorized code execution.
How do I fix CVE-2025-32702?
To fix CVE-2025-32702, update to the latest version of Visual Studio as outlined in the vendor's security advisories.
Which versions of Visual Studio are affected by CVE-2025-32702?
CVE-2025-32702 affects Visual Studio 2022 versions 17.8, 17.10, and 17.12, as well as Visual Studio 2019 version 16.11.
Can CVE-2025-32702 lead to remote code execution?
No, CVE-2025-32702 specifically allows local code execution due to command injection vulnerabilities.
Is there a patch available for CVE-2025-32702?
Yes, patches are available for the affected versions of Visual Studio to mitigate CVE-2025-32702.