CVE-2021-34529
published 2021-07-14CVE-2021-34529: Visual Studio Code Remote Code Execution Vulnerability
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.86%
88.9th percentile
Visual Studio Code Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio_code | < 1.57.1 | 1.57.1 |
| microsoft | visual_studio_code | >= 1.0.0 < 1.57.1 | 1.57.1 |
| msrc | visual_studio_code | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Visual Studio Code Remote Code Execution Vulnerability
vendor_msrc·2021-07-13·CVSS 7.8
CVE-2021-34529 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
FAQ: How does Visual Studio Code protect against remote code execution vulnerabilities in extensions?
With the release of Visual Studio Code 1.57, a new feature was added called Workspace Trust. This new feature allows developers to open unfamiliar code or extensions in Restricted Mode with the option to later mark the code as trusted. Restricted Mode works to prevent the automatic execution of code by restricting accessing to certain VS Code features. More details about this new functionality can be found here - https://code.visualstudio.com/updates/v1_57#_workspace-trust.
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Re
GHSA
GHSA-8h7g-r6fh-x7wp: Visual Studio Code Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34528
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-34529 [HIGH] GHSA-8h7g-r6fh-x7wp: Visual Studio Code Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34528
Visual Studio Code Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34528.
GHSA
GHSA-97m5-wjh8-vrcx: Visual Studio Code Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34529
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-34528 [HIGH] GHSA-97m5-wjh8-vrcx: Visual Studio Code Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34529
Visual Studio Code Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34529.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-14
Published