CVE-2025-55240
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-17
Assigner: Microsoft Corporation
Description
Description
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | visual_studio_2017 | From 15.0 (inc) to 15.9.77 (exc) |
| microsoft | visual_studio_2019 | From 16.0 (inc) to 16.11.52 (exc) |
| microsoft | visual_studio_2022 | From 17.10.0 (inc) to 17.10.20 (exc) |
| microsoft | visual_studio_2022 | From 17.12.0 (inc) to 17.12.13 (exc) |
| microsoft | visual_studio_2022 | From 17.14.0 (inc) to 17.14.17 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |