Impact
This vulnerability is caused by an improper limitation of a pathname to a restricted directory, enabling path traversal attacks. An attacker who can influence the path used by Visual Studio Code may manipulate files outside the intended directory, allowing tampering with code or configuration files over the network. The weakness is identified as CWE-22.
Affected Systems
Microsoft Visual Studio Code is affected. No specific version ranges are provided in the CNA data, so all installations that have not applied the patch are considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker can provide a specially crafted path that is processed by Visual Studio Code or its extensions. Successful exploitation would allow the attacker to tamper with files accessible to the application, potentially leading to code injection or privilege escalation if additional weaknesses exist.
OpenCVE Enrichment