7.3

CVE-2025-24998

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
MicrosoftVisual Studio 2017 Version >= 15.0 < 15.9.71
MicrosoftVisual Studio 2019 Version >= 16.0 < 16.11.45
MicrosoftVisual Studio 2022 Version >= 17.8.0 < 17.8.19
MicrosoftVisual Studio 2022 Version >= 17.10.0 < 17.10.12
MicrosoftVisual Studio 2022 Version >= 17.12.0 < 17.12.6
MicrosoftVisual Studio 2022 Version >= 17.13.0 < 17.13.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.504
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.