CVE-2025-26631

CWE-4274 documents4 sources
Severity
7.3HIGH
EPSS
0.6%
top 30.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft/visual_studio_code1.0.01.98.0

🔴Vulnerability Details

2
GHSA
GHSA-4426-5gmw-3hrf: Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally2025-03-11
CVEList
Visual Studio Code Elevation of Privilege Vulnerability2025-03-11

📋Vendor Advisories

1
Microsoft
Visual Studio Code Elevation of Privilege Vulnerability2025-03-11