Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 88.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 88.00 |
VPI formula vpi-v1
This CVE is referenced in a KISA security bulletin (Korean only).