cbcvebase.
CVE-2025-49739
published 2025-07-08

CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Affected

21 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_visual_studio_2015_update_3>= 14.0.0 < 14.0.27564.014.0.27564.0
microsoftmicrosoft_visual_studio_2017_version_15.9>= 15.9.0 < 15.9.7515.9.75
microsoftmicrosoft_visual_studio_2019_version_16.11>= 16.11.0 < 16.11.4916.11.49
microsoftmicrosoft_visual_studio_2022_version_17.10>= 17.10.0 < 17.10.1717.10.17
microsoftmicrosoft_visual_studio_2022_version_17.12>= 17.12.0 < 17.12.1017.12.10
microsoftmicrosoft_visual_studio_2022_version_17.14>= 17.14.0 < 17.14.817.14.8
microsoftmicrosoft_visual_studio_2022_version_17.8>= 17.8.0 < 17.8.2317.8.23
microsoftvisual_studio
microsoftvisual_studio_2017>= 15.0 < 15.9.7515.9.75
microsoftvisual_studio_2019>= 16.0 < 16.11.4916.11.49
microsoftvisual_studio_2022>= 17.10.0 < 17.10.1717.10.17
microsoftvisual_studio_2022>= 17.12.0 < 17.12.1017.12.10
microsoftvisual_studio_2022>= 17.14.0 < 17.14.817.14.8
microsoftvisual_studio_2022>= 17.8.0 < 17.8.2317.8.23
msrcmicrosoft_visual_studio_2015_update_3
msrcmicrosoft_visual_studio_2017_version_15.9
msrcmicrosoft_visual_studio_2019_version_16.11
msrcmicrosoft_visual_studio_2022_version_17.10
msrcmicrosoft_visual_studio_2022_version_17.12
msrcmicrosoft_visual_studio_2022_version_17.14
msrcmicrosoft_visual_studio_2022_version_17.8