Impact
In Visual Studio Code, an incorrectly resolved name or reference can be exploited by an unauthorized attacker to disclose information across a network. The flaw allows remote access to data that the attacker should not see, potentially exposing configuration details, credentials, or other sensitive content. The weakness is classified as CWE-706, reflecting misuse of authority or privileges.
Affected Systems
The affected product is Microsoft Visual Studio Code. No specific version information is defined in the vulnerability data, so any installation of Visual Studio Code that has not applied Microsoft’s latest security update is potentially at risk.
Risk and Exploitability
With a CVSS score of 7.4 the vulnerability represents a high risk to confidentiality. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires network connectivity to the instance running VS Code, such as through remote debugging or extension management features, and the attacker must be able to send malformed requests that trigger the name resolution error.
OpenCVE Enrichment