CVE-2025-21206
published 2025-02-11CVE-2025-21206: Visual Studio Installer Elevation of Privilege Vulnerability
PriorityP337high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.68%
48.1th percentile
Visual Studio Installer Elevation of Privilege Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2017_version_15.9 | >= 15.9.0 < 15.9.70 | 15.9.70 |
| microsoft | microsoft_visual_studio_2019_version_16.11 | >= 16.11.0 < 16.11.44 | 16.11.44 |
| microsoft | microsoft_visual_studio_2022_version_17.10 | >= 17.10.0 < 17.10.11 | 17.10.11 |
| microsoft | microsoft_visual_studio_2022_version_17.12 | >= 17.12.0 < 17.12.5 | 17.12.5 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.18 | 17.8.18 |
| microsoft | visual_studio_2017 | >= 15.0 < 15.9.70 | 15.9.70 |
| microsoft | visual_studio_2019 | >= 16.0 < 16.11.44 | 16.11.44 |
| microsoft | visual_studio_2022 | >= 17.10 < 17.10.11 | 17.10.11 |
| microsoft | visual_studio_2022 | >= 17.12 < 17.12.5 | 17.12.5 |
| microsoft | visual_studio_2022 | >= 17.8 < 17.8.18 | 17.8.18 |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Visual Studio Installer Elevation of Privilege Vulnerability
vendor_msrc·2025-02-11·CVSS 7.3
CVE-2025-21206 [HIGH] CWE-427 Visual Studio Installer Elevation of Privilege Vulnerability
Visual Studio Installer Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of this vulnerability requires that a local user executes the Visual Studio installer
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
Visual Studio: Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation o
GHSA
GHSA-rg59-phq2-352q: Visual Studio Installer Elevation of Privilege Vulnerability
ghsa_unreviewed·2025-02-11
CVE-2025-21206 [HIGH] CWE-427 GHSA-rg59-phq2-352q: Visual Studio Installer Elevation of Privilege Vulnerability
Visual Studio Installer Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
2025-02-11
Published