Cyber Posture

CVE-2025-21178

High

Published: 14 January 2025

Published
14 January 2025
Modified
27 January 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0036 57.9th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

Visual Studio Remote Code Execution Vulnerability

Security Summary

CVE-2025-21178 is a Remote Code Execution vulnerability affecting Visual Studio. Published on 2025-01-14T18:15:30.847, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWEs-122, CWE-125, and NVD-CWE-noinfo.

The vulnerability enables remote code execution over a network connection with low attack complexity and no required privileges on the target system, though it requires user interaction to trigger. Successful exploitation grants an attacker high-impact access to confidentiality, integrity, and availability, potentially allowing arbitrary code execution in the context of the affected Visual Studio process.

Microsoft's update guide provides details on mitigation and patching for this vulnerability, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21178.

Details

CWE(s)
CWE-122CWE-125NVD-CWE-noinfo

Affected Products

microsoft
visual studio 2017
15.0 — 15.9.69
microsoft
visual studio 2019
16.0 — 16.11.43
microsoft
visual studio 2022
17.6.0 — 17.6.22 · 17.8.0 — 17.8.17 · 17.10.0 — 17.10.10

References