Insecure DLL loading in Microsoft SQL Server Management Studio and Microsoft Visual Studio Tools for Applications - CVE-2025-29803

 

Insecure DLL loading in Microsoft SQL Server Management Studio and Microsoft Visual Studio Tools for Applications - CVE-2025-29803

Published: April 9, 2025


Vulnerability identifier: #VU107291
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-29803
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Microsoft SQL Server Management Studio
Microsoft Visual Studio Tools for Applications

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner within Visual Studio Tools for Applications and SQL Server Management Studio. A remote user can place a specially crafted .dll file and gain elevated privileges on the system.


How to mitigate CVE-2025-29803

Install updates from vendor's website.

Sources