Impact
The vulnerability arises from an incomplete comparison that neglects critical factors in Visual Studio Code, enabling an attacker who can send crafted data over a network to bypass a protection mechanism. This bypass permits unauthorized operations on the installation, potentially including modified configuration, execution of unintended commands, or privilege escalation within the editor environment. The weakness maps to CWE‑1023 (Improper Comparison of Other Than Two Objects) and CWE‑693 (Insufficient Logging & Monitoring).
Affected Systems
Microsoft Visual Studio Code is affected. No specific versions are listed in the advisory, so all releases should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.6 classifies the vulnerability as critical, with a high likelihood of exploitation if an attacker can reach the target over the network. The EPSS is not available, so exact usage probability is unknown, but the advisory’s description suggests that network exposure is required. The issue is not currently listed in CISA’s KEV catalog. Given its criticality and potential for remote bypass, the risk to systems that run unpatched Visual Studio Code is pronounced, especially in environments where the editor is exposed to untrusted inputs or network connections.
OpenCVE Enrichment