Insecure DLL loading in Microsoft SQL Server Management Studio and Microsoft Visual Studio Tools for Applications - CVE-2025-29803

 

Insecure DLL loading in Microsoft SQL Server Management Studio and Microsoft Visual Studio Tools for Applications - CVE-2025-29803

Published: April 9, 2025


Vulnerability identifier: #VU107291
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-29803
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner within Visual Studio Tools for Applications and SQL Server Management Studio. A remote user can place a specially crafted .dll file and gain elevated privileges on the system.


Affected software

Microsoft SQL Server Management Studio
Microsoft Visual Studio Tools for Applications

How to mitigate CVE-2025-29803

Install updates from vendor's website.


External References

Related Security Bulletins