CVE-2025-29803
HIGHMicrosoft Sql Server Management Studio - Uncontrolled Search Path
Title source: ruleDescription
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Scores
CVSS v3
7.3
EPSS
0.0046
EPSS Percentile
63.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (5)
microsoft/sql_server_management_studio
< 20.2.1
microsoft/visual_studio_tools_for_applications_2019
< 16.0.35907.0
microsoft/visual_studio_tools_for_applications_2019_sdk
< 16.0.35907.0
microsoft/visual_studio_tools_for_applications_2022
< 17.0.35906.0
microsoft/visual_studio_tools_for_applications_2022_sdk
< 17.0.35906.0
Timeline
Published
Apr 12, 2025
Tracked Since
Feb 18, 2026