CVE-2025-49739 - CVE House
Back to Database
Status published High CVE-2025-49739

Visual Studio Elevation of Privilege Vulnerability

Vulnerability Description

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49739

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Microsoft Visual Studio 2015 Update 3, Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8), Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10), Microsoft Visual Studio 2022 version 17.10, Microsoft Visual Studio 2022 version 17.12, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2022 version 17.8
Vulnerable Versions:
14.0.0, 15.9.0, 16.11.0, 17.10.0, 17.12.0, 17.14.0, 17.8.0

Timeline

Official Publish: July 8th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Weaknesses (CWE)