Impact
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network, enabling them to perform actions beyond their intended permissions. This flaw is an improper access control weakness that can result in unauthorized access to system resources and potentially compromise the integrity of the host.
Affected Systems
Microsoft Visual Studio Code. No specific version information is disclosed, so the vulnerability could affect any currently deployed installation.
Risk and Exploitability
The issue has a CVSS score of 9.6, indicating critical severity. An EPSS score of <1% suggests a low yet non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment