Impact
A missing authorization check in Microsoft Visual Studio Code permits an unauthenticated attacker to run arbitrary code over the network. The flaw enables full control over the victim system via the Editor’s remote capabilities, leading to loss of confidentiality, integrity, and availability.
Affected Systems
All versions of Visual Studio Code distributed by Microsoft are potentially vulnerable. No specific version range is listed, so the issue should be assumed to affect all releases until a patch is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating a high severity level. EPSS data are not available, but the absence of a CISA KEV listing does not reduce the risk given the nature of the flaw. The likely attack vector is a network-based request that exploits the missing authorization, meaning an attacker only needs network connectivity to the target device to trigger code execution.
OpenCVE Enrichment