Microsoft Visual Studio Code, visual studio code
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.