CVE-2025-64660

Severity
8.0HIGH
EPSS
0.1%
top 66.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20
Latest updateNov 21

Description

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft/visual_studio_code1.0.01.106.2

🔴Vulnerability Details

2
GHSA
GHSA-j8xq-6qq7-vfv7: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature over a network2025-11-21
CVEList
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability2025-11-20

📋Vendor Advisories

1
Microsoft
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability2025-11-11