CVE-2025-32703

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*

History

19 May 2025, 18:30

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32703 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32703 - Vendor Advisory
CPE cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
Summary
  • (es) La granularidad insuficiente del control de acceso en Visual Studio permite que un atacante autorizado divulgue información localmente.
First Time Microsoft
Microsoft visual Studio 2022
Microsoft visual Studio 2017
Microsoft visual Studio 2019

13 May 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 17:16

Updated : 2025-05-19 18:30


NVD link : CVE-2025-32703

Mitre link : CVE-2025-32703

CVE.ORG link : CVE-2025-32703


JSON object : View

Products Affected

microsoft

  • visual_studio_2017
  • visual_studio_2019
  • visual_studio_2022
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-1220

Insufficient Granularity of Access Control

NVD-CWE-noinfo