Status: UPDATED | Advisory ID: CVE-2026-70335
| CVE | CVE-2026-70335 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Microsoft visual_studio_code and Microsoft Visual Studio Code |
| Classified as | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Microsoft | visual_studio_code | ||
| Microsoft | Visual Studio Code |
| Subsystems | General OT |
| Sectors | Multiple |
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.