{"dataType": "CVE_RECORD", "containers": {"cna": {"metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.3, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}}], "affected": [{"cpes": ["cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019:*:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "visual_studio_tools_for_applications_2019", "versions": [{"status": "affected", "version": "16.0", "lessThan": "16.0.35907.0", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:visual_studio_tools_for_applications_2022:*:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "visual_studio_tools_for_applications_2022", "versions": [{"status": "affected", "version": "17.0", "lessThan": "17.0.35906.0", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2019_sdk:*:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "visual_studio_tools_for_applications_2019_sdk", "versions": [{"status": "affected", "version": "16.0", "lessThan": "16.0.35907.0", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:microsoft:visual_studio_tools_for_applications_2022_sdk:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "visual_studio_tools_for_applications_2022_sdk", "versions": [{"status": "affected", "version": "17.0", "lessThan": "17.0.35906.0", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:microsoft:sql_server_management_studio:*:*:*:*:*:*:*:*"], "vendor": "microsoft", "product": "sql_server_management_studio", "versions": [{"status": "affected", "version": "20.0", "lessThan": "20.2.37.0", "versionType": "custom"}], "defaultStatus": "unaffected"}], "references": [{"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29803"}], "descriptions": [{"lang": "en", "value": "Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally."}], "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-427", "description": "CWE-427"}]}], "providerMetadata": {"orgId": "00000000-0000-4000-A000-000000000003", "shortName": "nvd", "dateUpdated": "2025-04-12T02:15:20Z", "x_subShortName": "nvd"}}}, "cveMetadata": {"cveId": "CVE-2025-29803", "state": "PUBLISHED", "dateUpdated": "2025-04-12T02:15:20Z", "assignerOrgId": "00000000-0000-4000-A000-000000000003", "datePublished": "2025-04-12T02:15:20Z", "assignerShortName": "nvd"}, "dataVersion": "5.0"}