Microsoft Visual Studio Code
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:-:*:*
A vulnerability allowing authorized attackers to bypass security features over the network has been identified in GitHub Copilot and Visual Studio Code. This issue arises from improper access control, which enables the exploitation of sensitive file protections in Visual Studio Code.
Exploitation of this vulnerability could lead to unauthorized bypassing of sensitive file protections in Visual Studio Code, allowing access to files that should be protected.
Users can download the security update for Visual Studio Code from the Visual Studio Code download page. Instructions for applying the update are available in the release notes for version 1.106.2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.