QID 375462

Date Published: 2021-04-19

QID 375462: Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

Visual Studio Code is a lightweight but powerful source code editor which runs on your desktop and is available for Windows, macOS and Linux.

Affected Versions:
Java Extension Pack for Visual Studio Code prior to version 0.28.0

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of Java Extension Pack for Visual Studio Code.

A local attacker who successfully exploited the vulnerability could inject arbitrary code to run in the context of the current user.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Please refer to Microsoft advisory for Visual Studio Code for more details.

    CVEs related to QID 375462

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-27084 Windows URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27084