Impact
Visual Studio Code contains a command‑injection flaw due to improper neutralization of special elements within command strings. This weakness, identified as CWE‑77, permits an attacker to craft input that is executed by the underlying operating‑system shell, allowing arbitrary code to run with the same privileges as the user running VS Code. An exploit could lead to compromise of confidentiality, integrity, or availability on the client machine.
Affected Systems
Microsoft Visual Studio Code is the affected product. Specific vulnerable releases are not enumerated in the available data, but any installation of VS Code that has not been updated to the latest version from the Microsoft security update guide may be at risk. Operators should verify the version and apply the published fix.
Risk and Exploitability
The CVSS score of 8.4 classifies the vulnerability as high severity. The EPSS score of <1 % indicates a low current probability of exploitation, and it is not currently listed in CISA’s KEV catalog. The attack likely requires an unauthorized user with local access to the machine to inject malicious commands; no publicly documented exploits are known. Nevertheless, the high potential impact warrants immediate remediation.
OpenCVE Enrichment