CVE-2025-32703: Microsoft Visual Studio 2017

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

Affected products

  • Microsoft Visual Studio 2017: from 15.0, before 15.9.73 (fixed in 15.9.73)
  • Microsoft Visual Studio 2019: from 16.0, before 16.11.47 (fixed in 16.11.47)
  • Microsoft Visual Studio 2022: from 17.8.0, before 17.8.21 (fixed in 17.8.21); from 17.10.0, before 17.10.14 (fixed in 17.10.14); from 17.12.0, before 17.12.8 (fixed in 17.12.8); from 17.13.0, before 17.13.7 (fixed in 17.13.7)

Published 2025-05-13. Last modified 2026-06-17.