Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-41613

Опубликовано: 12 мая 2026
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Visual Studio Code Elevation of Privilege Vulnerability

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability?

A successful attacker could obtain the permissions associated with the MCP Server’s managed identity. This may allow the attacker to access or perform actions on any resources that the managed identity is authorized to reach. The attacker does not gain broader tenant‑level or administrator permissions; only those tied to the compromised managed identity.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

The user would have be enticed to open a malicious file in vscode. Users should never open anything that they do not know or trust to be safe.

Обновления

ПродуктСтатьяОбновление
Visual Studio Code

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 41%
0.0052
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость редактора исходного кода Microsoft Visual Studio Code, связанная с ошибками управления сеансом, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 41%
0.0052
Низкий

8.8 High

CVSS3