QID 376164

Date Published: 2021-12-15

QID 376164: Visual Studio Code WSL Extension Remote Code Execution (RCE) Vulnerability for December 2021

Visual Studio Code Windows Subsystem for Linux (WSL) Extension has the Remote Code Execution Vulnerability

Affected Versions:
0.63.11

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of Visual Studio Code with WSL extension.

Visual Studio Code WSL extension is prone to remote code execution vulnerability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to CVE-2021-43907for more information pertaining to these vulnerabilities.

    CVEs related to QID 376164

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-43907 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43907