CVE-2025-47959
published 2025-06-13CVE-2025-47959: Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a…
PriorityP348high7.1CVSS 3.1
AVNACHPRLUIRSUCHIHAH
EPSS
6.66%
93.2th percentile
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2022_version_17.10 | >= 17.10.0 < 17.10.16 | 17.10.16 |
| microsoft | microsoft_visual_studio_2022_version_17.12 | >= 17.12.0 < 17.12.9 | 17.12.9 |
| microsoft | microsoft_visual_studio_2022_version_17.14 | >= 17.14.0 < 17.14.5 | 17.14.5 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.22 | 17.8.22 |
| microsoft | visual_studio_2022 | >= 17.10.0 < 17.10.16 | 17.10.16 |
| microsoft | visual_studio_2022 | >= 17.12.0 < 17.12.9 | 17.12.9 |
| microsoft | visual_studio_2022 | >= 17.14.0 < 17.14.5 | 17.14.5 |
| microsoft | visual_studio_2022 | >= 17.8.0 < 17.8.22 | 17.8.22 |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.14 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ch2f-3gv8-q5g5: Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code ove
ghsa_unreviewed·2025-06-13
CVE-2025-47959 [HIGH] CWE-77 GHSA-ch2f-3gv8-q5g5: Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code ove
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
Microsoft
Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2025-06-10·CVSS 7.1
CVE-2025-47959 [HIGH] CWE-77 Visual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Description: Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires that the target system be set up in a specific manner and the attacker to have knowledge of that setup.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authorized attacker with standard user privileges could place a malicious file in an online directory or in a local network location and t
No detection rules found.
No public exploits indexed.
2025-06-13
Published