CVE-2025-24998
published 2025-03-11CVE-2025-24998: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
PriorityP337high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.43%
34.7th percentile
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2017_version_15.9 | >= 15.9.0 < 15.9.71 | 15.9.71 |
| microsoft | microsoft_visual_studio_2019_version_16.11 | >= 16.11.0 < 16.11.45 | 16.11.45 |
| microsoft | microsoft_visual_studio_2022_version_17.10 | >= 17.10.0 < 17.10.12 | 17.10.12 |
| microsoft | microsoft_visual_studio_2022_version_17.12 | >= 17.12.0 < 17.12.6 | 17.12.6 |
| microsoft | microsoft_visual_studio_2022_version_17.13 | >= 17.13.0 < 17.13.3 | 17.13.3 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.19 | 17.8.19 |
| microsoft | visual_studio_2017 | >= 15.0 < 15.9.71 | 15.9.71 |
| microsoft | visual_studio_2019 | >= 16.0 < 16.11.45 | 16.11.45 |
| microsoft | visual_studio_2022 | >= 17.10.0 < 17.10.12 | 17.10.12 |
| microsoft | visual_studio_2022 | >= 17.12.0 < 17.12.6 | 17.12.6 |
| microsoft | visual_studio_2022 | >= 17.13.0 < 17.13.3 | 17.13.3 |
| microsoft | visual_studio_2022 | >= 17.8.0 < 17.8.19 | 17.8.19 |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.13 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_oracle7.5HIGH
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-565c-x77x-j8h4: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2025-03-11
CVE-2025-24998 [HIGH] CWE-427 GHSA-565c-x77x-j8h4: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
Oracle
Oracle Oracle Analytics Risk Matrix: Development Operations (Apache Commons FileUpload) — CVE-2023-24998
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2023-24998 [HIGH] Oracle Oracle Analytics Risk Matrix: Development Operations (Apache Commons FileUpload) — CVE-2023-24998
Oracle Oracle Analytics Risk Matrix: Development Operations (Apache Commons FileUpload) vulnerability
CVE: CVE-2023-24998
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Microsoft
Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2025-03-11·CVSS 7.3
CVE-2025-24998 [HIGH] CWE-427 Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Description: Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
FAQ: According to the CVSS metric, the attack vector is local (AV:L), privileges are low (PR:L), and user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires an authenticated attacker to place a specially crafted .dll file in a local network location. When a victim runs this file, it loads the malicious DLL.
Visual Studio: Visual Studio
Microsoft: Microsoft
Customer
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Commons FileUpload) — CVE-2023-24998
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2023-24998 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Commons FileUpload) — CVE-2023-24998
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Commons FileUpload) vulnerability
CVE: CVE-2023-24998
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
No detection rules found.
No public exploits indexed.
2025-03-11
Published