Security Updates for Microsoft Visual Studio Products (February 2025)

high Nessus Plugin ID 216241

Synopsis

The Microsoft Visual Studio Products are affected by a privelige elevation vulnerability

Description

The Microsoft Visual Studio Products are missing security updates. It is, therefore, affected by a privilege elevation vulnerability.
- An attacker could exploit the flaw to gain higher-level access privileges than they are normally allowed. Specifically, in this case, the weakness lies within the Visual Studio Installer. When exploited, it could allow a malicious user or process to bypass certain security controls, potentially resulting in unauthorized system access. This kind of vulnerability is particularly dangerous because it may empower an attacker with administrative rights, granting them the ability to install software, delete files, or even take over system functions. (CVE-2025-21206)

Solution

Microsoft has released the following security updates to address this issue:
- Update 17.12.5 for Visual Studio 2022
- Update 17.10.11 for Visual Studio 2022
- Update 17.8.18 for Visual Studio 2022
- Update 16.11.44 for Visual Studio 2019
- Update 15.9.70 for Visual Studio 2017

Plugin Details

Severity: High

ID: 216241

File Name: smb_nt_ms25_feb_visual_studio.nasl

Version: 1.3

Type: local

Agent: windows

Published: 2/13/2025

Updated: 2/19/2025

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-21206

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:visual_studio

Required KB Items: SMB/MS_Bulletin_Checks/Possible, installed_sw/Microsoft Visual Studio, SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2025

Vulnerability Publication Date: 1/14/2025

Reference Information

CVE: CVE-2025-21206

IAVA: 2025-A-0107