CVE-2025-29803 - CVE House
Back to Database
Status published High CVE-2025-29803

Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability

Vulnerability Description

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29803

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SQL Server Management Studio 20.2, Visual Studio Tools for Applications (VSTA), VSTA 2019 SDK, VSTA 2022 SDK
Vulnerable Versions:
20.0, 16.0, 17.0

Timeline

Official Publish: April 12th, 2025
Last Modified: February 13th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Weaknesses (CWE)