← Back

CVE-2025-49739

nvd nist
Published: Jul 8, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Affected (7)

4 products
Visual Studio
Visual Studio 2017
Visual Studio 2019
Visual Studio 2022
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 2015 update3
From 15.0 to 15.9.75
From 16.0 to 16.11.49
Microsoft
From 17.10.0 to 17.10.17
From 17.12.0 to 17.12.10
From 17.14.0 to 17.14.8
From 17.8.0 to 17.8.23

References (1)

Timeline

No history available yet.