CVE-2025-21178
Published: 14 January 2025
Description
Visual Studio Remote Code Execution Vulnerability
Security Summary
CVE-2025-21178 is a Remote Code Execution vulnerability affecting Visual Studio. Published on 2025-01-14T18:15:30.847, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWEs-122, CWE-125, and NVD-CWE-noinfo.
The vulnerability enables remote code execution over a network connection with low attack complexity and no required privileges on the target system, though it requires user interaction to trigger. Successful exploitation grants an attacker high-impact access to confidentiality, integrity, and availability, potentially allowing arbitrary code execution in the context of the affected Visual Studio process.
Microsoft's update guide provides details on mitigation and patching for this vulnerability, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21178.
Details
- CWE(s)