漏洞概述 漏洞名称: Visual Studio Code Security Feature Bypass Vulnerability CVE编号: CVE-2026-57102 发布日期: 2026年7月14日 分配CNA: Microsoft CVSS评分: 3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C CVSS版本: 3.1.8.8 / 7.7 影响范围 影响类型: Security Feature Bypass 最大严重程度: Important 弱点: 1. CVE-029: Inclusion of Functionality from Untrusted Control Sphere 2. CVE-200: Exposure of Sensitive Information to an Unauthorized Actor 修复方案 CVSS Source: Microsoft Base score metrics (8): - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Confidentiality: High - Integrity: High - Availability: High POC代码或利用代码 页面中未包含POC代码或利用代码。 总结 该漏洞涉及Visual Studio Code的安全功能绕过,可能导致敏感信息泄露和功能从不受信任的控制域包含。最大严重程度为重要,CVSS评分为7.7。目前没有提供具体的修复方案或POC代码。