Impact
The vulnerability involves a user‑controlled key that allows an attacker to bypass a security feature in Visual Studio Code. Because the key is not properly authenticated, an attacker can trigger the bypass without legitimate authorization, effectively undermining the intended protection. This type of flaw is classified as an authorization bypass (CWE‑639).
Affected Systems
Affected systems are installations of Microsoft Visual Studio Code. The CVE does not list specific version ranges, so all unsupported or earlier releases that contain the vulnerable component are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the lack of an EPSS entry means an exploitation probability has not been quantified. The vulnerability is not yet listed in the CISA KEV catalog. Attackers would likely target the network‑facing aspects of the editor, for example via malicious extensions or networked development environments, to deliver the user‑controlled key. Because the bypass is achieved over a network, remote attackers can gain elevated privileges without local interaction.
OpenCVE Enrichment