CVE-2025-49739

CWE-594 documents4 sources

Description

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages11 packages

NVDmicrosoft/visual_studio_201715.015.9.75
NVDmicrosoft/visual_studio_201916.016.11.49
NVDmicrosoft/visual_studio_202217.8.017.8.23+3
CVEListV5microsoft/microsoft_visual_studio_2015_update_314.0.014.0.27564.0

🔴Vulnerability Details

2
GHSA
GHSA-cf69-g2cj-5w8c: Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network2025-07-08
CVEList
Visual Studio Elevation of Privilege Vulnerability2025-07-08

📋Vendor Advisories

1
Microsoft
Visual Studio Elevation of Privilege Vulnerability2025-07-08
CVE-2025-49739 (HIGH CVSS 8.8) | Improper link resolution before fil | cvebase.io