QID 377627

Date Published: 2022-10-12

QID 377627: Microsoft Visual Studio Code Security Update for October 2022

Visual Studio Code is a lightweight but powerful source code editor which runs on your desktop and is available for Windows, macOS and Linux.

Affected Versions:
Visual studio code prior to version 1.72.1

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of Visual Studio Code.

Visual Studio Code is prone to Remote Code Execution and Information Disclosure impacting confidentiality, integrity and availablity

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Customers are advised to refer to CVE-2022-41034 and CVE-2022-41042 for more information pertaining to this vulnerability.

    CVEs related to QID 377627

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-41034 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41034
    CVE-2022-41042 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41042