PT-2025-20428 · Microsoft · Visual Studio

Cameron Vincent

·

Published

2025-05-08

·

Updated

2025-07-18

·

CVE-2025-29813

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Visual Studio (affected versions not specified)
Description An elevation of privilege issue exists due to improper handling of pipeline job tokens by Visual Studio. This could allow an attacker to extend their access to a project if they already have access and can swap a short-term token for a long-term one. The issue is addressed by correcting how the Visual Studio updater handles these tokens.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-06316
CVE-2025-29813

Affected Products

Visual Studio