Impact
An attacker who can execute code locally can exploit an incorrect authorization check in Visual Studio Code to bypass a built‑in security feature. The flaw is rooted in improper handling of authority and privilege escalation weaknesses (CWE‑693 and CWE‑863). Because the security property is locally enforced, an attacker can gain unauthorized access to protected functionality or data that the feature is meant to guard, potentially compromising confidentiality or integrity of the user's environment.
Affected Systems
Microsoft Visual Studio Code on any machine where the vulnerable version is installed. No specific version range was supplied, so all currently installed releases are potentially affected until a fix is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local due to the requirement for local code execution; a remote attacker would need to compromise the local system first.
OpenCVE Enrichment