Microsoft Visual Studio Code
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*, +6 more
A session fixation vulnerability has been identified in Visual Studio Code, allowing unauthorized attackers to elevate privileges over a network. This vulnerability affects Visual Studio Code versions prior to 1.119.1.
Exploitation of this vulnerability could lead to unauthorized privilege elevation, allowing an attacker to gain access to resources and perform actions associated with the compromised managed identity on the MCP Server.
Users are advised to update to Visual Studio Code version 1.119.1 or later. The security update is available for download from the Visual Studio Code website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.