PT-2025-6298 · Microsoft · Visual Studio

Karan Bamal

+2

·

Published

2025-02-11

·

Updated

2025-02-27

·

CVE-2025-21206

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Visual Studio (affected versions not specified)
Description: The issue is related to an elevation of privilege vulnerability in the Visual Studio installer, which is associated with an uncontrolled search path element. Exploitation of this issue may allow an attacker to elevate their privileges.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2025-01539
CVE-2025-21206

Affected Products

Visual Studio