Impact
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. This indicates an improper access control weakness where authentication is bypassed, enabling the attacker to gain higher privileges and perform actions beyond the intended scope of the application.
Affected Systems
Microsoft Visual Studio Code. No specific version information is disclosed, so the vulnerability could affect any currently deployed installation.
Risk and Exploitability
The issue has a CVSS score of 9.6, indicating critical severity. An EPSS score of <1% suggests a low yet non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description explicitly states that the vulnerability can be exploited over a network connection, though the exact conditions and prerequisites are not detailed in the available data.
OpenCVE Enrichment