CVE-2025-32703
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: secure@microsoft.com (Secondary)
Description
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
Affected (6)
Products: Microsoft: Visual Studio 2017, Visual Studio 2019, Visual Studio 2022
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.0 to 15.9.73 | |
| From 16.0 to 16.11.47 | |
| From 17.10.0 to 17.10.14 |
Related CWEs
CWE-1220
Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References (1)
Source: secure@microsoft.com
Vendor Advisory
Timeline
No history available yet.