Impact
Visual Studio Code does not enforce a required security check, causing a fail‑open behaviour that allows an attacker to bypass a security feature over a network. The flaw permits unauthorized access to protected functionality. This vulnerability is classified as CWE‑636, indicating that the problem arises from a failure to validate or sanitize input or safeguards, enabling a bypass of intended controls.
Affected Systems
Microsoft Visual Studio Code. Any installation that has not applied the patch announced by Microsoft is potentially vulnerable. No specific version range is provided, so all unpatched versions could be affected.
Risk and Exploitability
The CVSS score of 8.2 classifies this issue as high severity. The EPSS score is below 1%, suggesting that exploitation attempts are currently rare or unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network connection to the affected Visual Studio Code instance; an attacker would need to initiate or intercept a network session to exploit the fail‑open behaviour.
OpenCVE Enrichment