CVE-2025-24998

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 427

Summary

CVE-2025-24998 is a newly disclosed vulnerability in Visual Studio that enables an attacker with authorized access to elevate privileges locally. This issue arises from an uncontrolled search path element, which allows the attacker to manipulate the application's environment variables and potentially execute arbitrary code. As a result, the attacker can gain elevated access to the system, potentially leading to significant security implications for organizations using Visual Studio. To mitigate this risk, it is recommended that users apply the latest patches and updates to their Visual Studio installations as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share