Impact
The vulnerability stems from the extension incorporating functionality that is under an untrusted control sphere. An attacker with local access to a compromised or unauthorized user account can trigger the extension’s security feature bypass, potentially allowing unauthorized actions or elevated privileges within the local machine. The weakness is classified under CWE-693 and CWE-829, indicating reliance on untrusted data and improper handling of external control over configuration.
Affected Systems
Microsoft’s Visual Studio Code Python extension is affected. No specific version details are provided in the available data, so any release that includes the vulnerable extension should be considered at risk until an official fix is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. EPSS information is not available, but the attack vector appears to be local, relying on an unauthorized local user. The vulnerability is not currently listed in CISA’s KEV catalog. Because the exploitation requires local presence, the risk is confined to compromised or malicious local accounts, but the potential impact is significant due to the privileged nature of the extension’s functionality.
OpenCVE Enrichment