Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14410 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. |
Mon, 19 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft visual Studio 2019 Microsoft visual Studio 2022 |
|
| CPEs | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft visual Studio 2019 Microsoft visual Studio 2022 |
Tue, 13 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | |
| Title | Visual Studio Remote Code Execution Vulnerability | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-26T18:28:26.704Z
Reserved: 2025-04-09T20:06:59.964Z
Link: CVE-2025-32702
Updated: 2025-05-13T17:33:14.900Z
Status : Analyzed
Published: 2025-05-13T17:16:02.903
Modified: 2025-05-19T18:30:28.383
Link: CVE-2025-32702
No data.
OpenCVE Enrichment
No data.
EUVD