CVE-2025-32703

Description

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDmicrosoft/visual_studio_201715.015.9.73
NVDmicrosoft/visual_studio_201916.016.11.47
NVDmicrosoft/visual_studio_202217.8.017.8.21+3

🔴Vulnerability Details

2
CVEList
Visual Studio Information Disclosure Vulnerability2025-05-13
GHSA
GHSA-c6v5-8q58-3543: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally2025-05-13

📋Vendor Advisories

1
Microsoft
Visual Studio Information Disclosure Vulnerability2025-05-13
CVE-2025-32703 (MEDIUM CVSS 5.5) | Insufficient granularity of access | cvebase.io