Impact
Visual Studio Code does not enforce a required security policy, allowing an attacker to circumvent a built‑in protection when accessed across a network. The flaw can lead to unauthorized execution or data exposure depending on the function that is bypassed. Because the failure is of type "failing open", the impacted system will automatically grant the attacker the privilege that the policy would normally restrict, raising confidentiality and integrity risks.
Affected Systems
The vulnerability belongs to Microsoft Visual Studio Code. No specific version information is listed, so all installations that may still contain the unpatched code could be susceptible.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, and the EPSS score, while not reported, does not adjust the perception of risk. The vulnerability is not currently included in the CISA KEV catalog. The attack vector is inferred to be over a network, as the description states that the bypass can occur via a network connection. An attacker would need to reach the affected workstation or server running VS Code to exploit the flaw.
OpenCVE Enrichment