#VU103827 Improper access control in Visual Studio Code - JS Debug Extension and Visual Studio Code - CVE-2025-24042
Published: February 11, 2025 / Updated: April 23, 2026
Visual Studio Code - JS Debug Extension
Visual Studio Code
Microsoft
Description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Visual Studio Code JS Debug Extension. A local user can place a specially crafted file on the machine running Visual Studio Code and gain elevated privilegeso n the system.