#VU107291 Insecure DLL loading in Microsoft SQL Server Management Studio and Microsoft Visual Studio Tools for Applications - CVE-2025-29803

 

#VU107291 Insecure DLL loading in Microsoft SQL Server Management Studio and Microsoft Visual Studio Tools for Applications - CVE-2025-29803

Published: April 9, 2025


Vulnerability identifier: #VU107291
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-29803
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft SQL Server Management Studio
Microsoft Visual Studio Tools for Applications
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner within Visual Studio Tools for Applications and SQL Server Management Studio. A remote user can place a specially crafted .dll file and gain elevated privileges on the system.


Remediation

Install updates from vendor's website.

External links