CNNVD-202511-2278 Information

CNNVD ID

CNNVD-202511-2278

CVE-2025-64660

  • CNNVD Published: 2025-11-20

Description (Chinese)

Microsoft Visual Studio Code是美国微软(Microsoft)公司的一款开源的代码编辑器。 Microsoft Visual Studio Code存在访问控制错误漏洞,该漏洞源于访问控制不当,可能导致绕过安全功能。

Description (English)

Microsoft Victoria Code is an open source code editor for Microsoft (MSC) in the United States. There is an error in access control in Microsoft Vital Studio Code, which stems from inadequate access control and may lead to the circumvention of security functions.

Hazard Level

Medium

Vulnerability Type

访问控制错误

Affected Vendor

微软

Published

2025-11-20

Last Modified

2026-02-24

References

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-64660 https://vigilance.fr/vulnerability/Visual-Studio-Code-file-write-via-Sensitive-File-Protections-Bypass-48823

Patch

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-64660

Share on: