Impact
An unauthorized attacker can bypass a security feature in the Microsoft Visual Studio Code CoPilot Chat Extension over a network. The flaw stems from an insufficient or missing authorization check, exposing the extension to privilege escalation or unauthorized data access depending on the protected functionality. Because the vulnerability is a feature bypass, the potential impact includes disclosure of restricted information or manipulation of the extension’s behavior.
Affected Systems
Microsoft Visual Studio Code CoPilot Chat Extension is the affected product. No specific version information is provided, indicating that all released revisions of the extension may be susceptible until Microsoft releases a patch. The extension operates within Visual Studio Code and interacts with the local system and network channels.
Risk and Exploitability
The CVSS score of 7.1 signals moderate to high severity. The EPSS score is reported as less than 1 percent, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring an attacker to communicate with the extension over a network session. Exploitation would require the extension to be active on the target machine and an adversary to offer a crafted request that triggers the missing authorization check.
OpenCVE Enrichment