Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 16.11.0 (custom) before 16.11.47
affected
17.10.0 (custom) before 17.10.14
affected
17.12.0 (custom) before 17.12.8
affected
17.13.0 (custom) before 17.13.7
affected
17.8.0 (custom) before 17.8.21
affected
Description
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32702 (Visual Studio Remote Code Execution Vulnerability)