CVE-2025-24998

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*

History

01 Jul 2025, 19:59

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24998 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24998 - Vendor Advisory
Summary
  • (es) El elemento de ruta de búsqueda no controlada en Visual Studio permite que un atacante autorizado eleve privilegios localmente.
First Time Microsoft
Microsoft visual Studio 2017
Microsoft visual Studio 2022
Microsoft visual Studio 2019
CPE cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*

11 Mar 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 17:16

Updated : 2025-07-01 19:59


NVD link : CVE-2025-24998

Mitre link : CVE-2025-24998

CVE.ORG link : CVE-2025-24998


JSON object : View

Products Affected

microsoft

  • visual_studio_2017
  • visual_studio_2022
  • visual_studio_2019
CWE
CWE-427

Uncontrolled Search Path Element