Vulnerability Description
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Sql Server Management Studio | < 20.2.1 |
| Microsoft | Visual Studio Tools For Applications 2019 | < 16.0.35907.0 |
| Microsoft | Visual Studio Tools For Applications 2019 Sdk | < 16.0.35907.0 |
| Microsoft | Visual Studio Tools For Applications 2022 | < 17.0.35906.0 |
| Microsoft | Visual Studio Tools For Applications 2022 Sdk | < 17.0.35906.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-29803?
CVE-2025-29803 is a vulnerability with a CVSS score of 7.3 (HIGH). Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
How severe is CVE-2025-29803?
CVE-2025-29803 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-29803?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Sql Server Management Studio, Microsoft Visual Studio Tools For Applications 2019, Microsoft Visual Studio Tools For Applications 2019 Sdk, Microsoft Visual Studio Tools For Applications 2022, Microsoft Visual Studio Tools For Applications 2022 Sdk.