Impact
A local attacker can manipulate a user‑controlled key within Visual Studio Code to bypass an authorization check, enabling the attacker to perform actions that should normally be restricted by the application's security feature. This flaw falls under CWE‑639 and permits the attacker to gain unauthorized privileged operations within the context of the user’s local environment. While the vulnerability only applies to local users, the impact includes potential exploitation of other protected resources accessed by the user.
Affected Systems
Microsoft Visual Studio Code is the affected product, as listed by the CNA. No specific version range is provided in the official entry, so the scope of affected releases cannot be determined from the available data, and all existing installations may be at risk until an updated revision is available.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The feature bypass can only be triggered by a local attacker who can supply the manipulated key value, and therefore it does not pose a remote threat. The vulnerability is not listed in the CISA KEV catalog, indicating that no known widespread exploitation has been recorded.
OpenCVE Enrichment