Microsoft Visual Studio Code
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*, +6 more
A security feature bypass vulnerability has been identified in Visual Studio Code. This issue arises from files or directories that are accessible to external parties, allowing an unauthorized attacker to locally bypass a security feature. Specifically, the vulnerability enables the bypassing of the Trusted Domain Service.
Exploitation of this vulnerability could lead to a significant loss of confidentiality, allowing an attacker to view sensitive information such as tokens. Additionally, it could result in some integrity loss by enabling changes to the disclosed information.
Users can update to Visual Studio Code version 1.100.1, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.