#VU103818 Insecure DLL loading in Visual Studio Code - CVE-2025-24039
Published: February 11, 2025 / Updated: April 23, 2026
Visual Studio Code
Microsoft
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner in Visual Studio Code. A local user can place a specially crafted .dll file, trick the victim into opening a file, associated with the vulnerable application and gain elevated privileges on the target system.