← Back

CVE-2025-32702

nvd nist
Published: May 13, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

Affected (5)

2 products
Visual Studio 2019
Visual Studio 2022
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
From 16.0 to 16.11.47
Microsoft
From 17.10.0 to 17.10.14
From 17.12.0 to 17.12.8
From 17.13.0 to 17.13.7
From 17.8.0 to 17.8.21

References (1)

Timeline

No history available yet.