QID 375452

Date Published: 2021-04-14

QID 375452: Visual Studio Code Remote Code Execution Vulnerability

Visual Studio Code is a lightweight but powerful source code editor which runs on your desktop and is available for Windows, macOS and Linux.

Affected Versions:
Visual studio code prior to version 1.55.2

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of visual studio code.

A local attacker who successfully exploited the vulnerability could inject arbitrary code to run in the context of the current user.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Please refer to Microsoft advisory for Visual Studio Code for more details.
    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-28469 MAC OS X URL Logo portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28469
    CVE-2021-28469 WIndows URL Logo portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28469