CVE-2025-26631
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 427
Summary
CVE-2025-26631 is a privilege escalation vulnerability affecting Visual Studio Code. An attacker who has already gained authorized access to the system can exploit this uncontrolled search path element to elevate their privileges locally, potentially gaining higher levels of access and control. This vulnerability poses a significant risk to organizations and individuals using Visual Studio Code, and it is recommended that affected users apply the available patch or update as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.