Impact
The vulnerability presents an interpretation conflict in Visual Studio Code that permits an unauthorized attacker to bypass a built‑in security feature when communicating over a network. Based on the description, it is inferred that such a bypass could enable the attacker to perform unauthorized configuration changes or expose sensitive data, but the exact post‑bypass capabilities are not explicitly detailed in the CVE text.
Affected Systems
Microsoft Visual Studio Code is affected. No specific version information is provided; the flaw applies to any installation that uses the described insecure interpretation logic.
Risk and Exploitability
The flaw carries a CVSS score of 8.2, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue, suggesting no publicly known exploitation. However, because the attack vector is over a network and the flaw permits a security feature bypass, the risk remains significant for systems that expose VS Code to external connections. An attacker who can reach the affected service may exploit this weakness to gain unauthorized control or compromise the integrity of the system.
OpenCVE Enrichment