QID 91794
Date Published: 2021-07-14
QID 91794: Visual Studio Code .NET Extensions Elevation of Privilege Vulnerability
Visual Studio Code is a lightweight but powerful source code editor which runs on your desktop and is available for Windows, macOS and Linux.
Affected Versions:
.NET Education Bundle SDK Install Tool Extension for Visual Studio Code prior to version 0.7.0.
.NET Install Tool for Authors Extension for Visual Studio Code prior to version 1.2.0.
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of .NET Education Bundle SDK Install Tool and .NET Install Tool for Authors Extension for Visual Studio Code.
Due to inaccurately scoped permissions being set on downloaded .NET install scripts, users are vulnerable to an elevation of privileges attack.
Solution
Please refer to Microsoft advisory for Visual Studio Code for more details.
Vendor References
- CVE-2021-34477 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-34477
CVEs related to QID 91794
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-34477 |
|