CVE-2025-32726
published 2025-04-12CVE-2025-32726: Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
PriorityP432medium6.8CVSS 3.1
AVLACLPRLUIRSUCHIHAL
EPSS
0.39%
31.4th percentile
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio_code | < 1.99.1 | 1.99.1 |
| microsoft | visual_studio_code | >= 1.0.0 < 1.99.1 | 1.99.1 |
| msrc | visual_studio_code | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
vendor_msrc6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c56x-xgv9-mcx5: Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2025-04-12
CVE-2025-32726 [MEDIUM] CWE-284 GHSA-c56x-xgv9-mcx5: Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Microsoft
Visual Studio Code Elevation of Privilege Vulnerability
vendor_msrc·2025-04-08·CVSS 6.8
CVE-2025-32726 [MEDIUM] CWE-284 Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
Description: Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could execute code in the context of another Visual Studio Code user on the vulnerable system.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), and integrity (I:H), and some loss of availability (A:L). What does that mean for this vulnerability?
An attacker who successfully exploited this vulnerability could view sensitive information (Confidentiality) and modify code in the rep
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-12
Published