CVE-2025-29803

HIGH

Microsoft Sql Server Management Studio - Uncontrolled Search Path

Title source: rule

Description

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 7.3
EPSS 0.0046
EPSS Percentile 63.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (5)

microsoft/sql_server_management_studio < 20.2.1
microsoft/visual_studio_tools_for_applications_2019 < 16.0.35907.0
microsoft/visual_studio_tools_for_applications_2019_sdk < 16.0.35907.0
microsoft/visual_studio_tools_for_applications_2022 < 17.0.35906.0
microsoft/visual_studio_tools_for_applications_2022_sdk < 17.0.35906.0

Timeline

Published Apr 12, 2025
Tracked Since Feb 18, 2026