CVE-2025-29803: Microsoft SQL Server Management Studio
High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft SQL Server Management Studio: before 20.2.1 (fixed in 20.2.1)
- Microsoft Visual Studio Tools For Applications 2019: before 16.0.35907.0 (fixed in 16.0.35907.0)
- Microsoft Visual Studio Tools For Applications 2019 SDK: before 16.0.35907.0 (fixed in 16.0.35907.0)
- Microsoft Visual Studio Tools For Applications 2022: before 17.0.35906.0 (fixed in 17.0.35906.0)
- Microsoft Visual Studio Tools For Applications 2022 SDK: before 17.0.35906.0 (fixed in 17.0.35906.0)
Published 2025-04-12. Last modified 2026-06-17.