QID 377628
Date Published: 2022-10-12
QID 377628: Microsoft Visual Studio Code Jupyter Extension Elevation of Privilege Vulnerability for October 2022
An attacker who successfully exploited this vulnerability could execute code in the context of another Visual Studio Code user on the vulnerable system.
Affected Versions:
2022.9.110
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of Visual Studio Code with Jupyter extension.
Visual Studio Code Jupyter extension is prone to privilege escalation vulnerability
Solution
Customers are advised to refer to CVE-2022-41083for more information pertaining to these vulnerabilities.
Workaround:
Create a folder C:\ProgramData\jupyter\kernels\ and configure it to be writable only by the current user
Workaround:
Create a folder C:\ProgramData\jupyter\kernels\ and configure it to be writable only by the current user
Vendor References
- CVE-2022-41083 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41083
CVEs related to QID 377628
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-41083 |
|