CVE-2025-32702: Microsoft Visual Studio 2019
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
Affected products
- Microsoft Visual Studio 2019: from 16.0, before 16.11.47 (fixed in 16.11.47)
- Microsoft Visual Studio 2022: from 17.8.0, before 17.8.21 (fixed in 17.8.21); from 17.10.0, before 17.10.14 (fixed in 17.10.14); from 17.12.0, before 17.12.8 (fixed in 17.12.8); from 17.13.0, before 17.13.7 (fixed in 17.13.7)
Published 2025-05-13. Last modified 2026-06-17.