CVE-2025-29803: Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability

7.3 CVSS

Description

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

Classification

CVE ID: CVE-2025-29803

CVSS Base Severity: HIGH

CVSS Base Score: 7.3

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Problem Types

CWE-427: Uncontrolled Search Path Element

Affected Products

Vendor: Microsoft, Microsoft, Microsoft, Microsoft, Microsoft

Product: Visual Studio Tools for Applications (VSTA), Visual Studio Tools for Applications (VSTA), VSTA 2022 SDK, VSTA 2019 SDK, SQL Server Management Studio 20.2

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 16.79% (scored less or equal to compared to others)

EPSS Date: 2025-04-16 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-29803
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29803

Timeline