« Back to list

CVE-2025-29804

Status: AnalyzedHigh (7.3)—

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L, UI:R y acceso de usuario autenticado (PR:L) indican explotación en cliente requiriendo interacción (T1203). El resultado es escalada de privilegios local confirmado en la descripción.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-29804",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-29804",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-08T18:37:52.223680Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Microsoft Visual Studio 2022 version 17.10",
          "versions": [
            {
              "status": "affected",
              "version": "17.10.0",
              "lessThan": "17.10.13",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Visual Studio 2022 version 17.12",
          "versions": [
            {
              "status": "affected",
              "version": "17.12.0",
              "lessThan": "17.12.7",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Visual Studio 2022 version 17.13",
          "versions": [
            {
              "status": "affected",
              "version": "17.13.0",
              "lessThan": "17.13.6",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Visual Studio 2022 version 17.8",
          "versions": [
            {
              "status": "affected",
              "version": "17.8.0",
              "lessThan": "17.8.20",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-08T18:16:06.180",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29804",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally."
    },
    {
      "lang": "es",
      "value": "El control de acceso inadecuado en Visual Studio permite que un atacante autorizado eleve privilegios localmente."
    }
  ],
  "lastModified": "2026-06-17T09:05:41.760",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "721FAAC5-CAF7-4741-AD98-7DA1E244CE93",
              "versionEndExcluding": "17.8.20",
              "versionStartIncluding": "17.8.0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8A53B16-AC32-4943-9532-5CA70A543A09",
              "versionEndExcluding": "17.10.13",
              "versionStartIncluding": "17.10.0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C403B4A3-41D8-454A-80F6-2DC9F31BE427",
              "versionEndExcluding": "17.12.7",
              "versionStartIncluding": "17.12.0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3093F62C-597E-47AA-9BE5-6FD2D5E98810",
              "versionEndExcluding": "17.13.6",
              "versionStartIncluding": "17.13.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}