CVE-2025-29803

HIGH

Microsoft Sql Server Management Studio - Uncontrolled Search Path

Title source: rule
STIX 2.1

Description

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 7.3
EPSS 0.0046
EPSS Percentile 64.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (5)
microsoft/sql_server_management_studio < 20.2.1
microsoft/visual_studio_tools_for_applications_2019 < 16.0.35907.0
microsoft/visual_studio_tools_for_applications_2019_sdk < 16.0.35907.0
microsoft/visual_studio_tools_for_applications_2022 < 17.0.35906.0
microsoft/visual_studio_tools_for_applications_2022_sdk < 17.0.35906.0
Published Apr 12, 2025
Tracked Since Feb 18, 2026