CVE-2024-43488
published 2024-10-08CVE-2024-43488: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.15%
63.2th percentile
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio_code | — | — |
| msrc | visual_studio_code | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-43488 affects the Visual Studio Code extension for Arduino; the extension has been deprecated and removed from the VS Code marketplace as of October 1, 2024. Detect presence of the extension in environments as a risk indicator. ↗
- →The vulnerability is exploitable via a network-based attack vector requiring no authentication; monitor for unexpected network connections originating from or targeting the VS Code Arduino extension process. ↗
- →The flaw stems from missing authentication for critical functions within the Arduino extension; alert on unauthenticated remote function calls to the extension's network-exposed interface. ↗
- ·Microsoft has fully mitigated this vulnerability server-side (cloud service CVE); no patch is available or planned since the extension is deprecated. Exploitation status is 'Less Likely' with no public exploit or active exploitation confirmed. ↗
- ·The extension will not receive a fix; Microsoft recommends migrating to Arduino IDE software instead of the VS Code extension. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Visual Studio Code extension for Arduino Remote Code Execution Vulnerability
vendor_msrc·2024-10-08·CVSS 8.8
CVE-2024-43488 [HIGH] CWE-306 Visual Studio Code extension for Arduino Remote Code Execution Vulnerability
Visual Studio Code extension for Arduino Remote Code Execution Vulnerability
Description: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
FAQ: Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?
This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.
Please see Toward greater transparency: Unveiling Cloud Service CVEs for more information.
FAQ: Where do I find the update for Visual Studio Code extension for Arduino?
Microsoft is not planning on fixing this vulner
GHSA
GHSA-7459-m7qw-m8fw: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code exe
ghsa_unreviewed·2024-10-08
CVE-2024-43488 [HIGH] CWE-306 GHSA-7459-m7qw-m8fw: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code exe
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe October 2024 Patch Tuesday Updates | Qualys
blogs_qualys·2024-10-08
Microsoft & Adobe October 2024 Patch Tuesday Updates | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for October 2024
- Adobe Patches for October 2024
- Zero-day Vulnerabilities Patched in October Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in October Patch Tuesday Edition
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Microsoft has rolled out its October 2024 Patch Tuesday updates, offering vital security fixes for IT professionals to implement. With several critical vulnerabilities patched, this release highlights the ongoing need for regular maintenance and attention to security.
## Microsoft P
Bleepingcomputer
Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws
blogs_bleepingcomputer·2024-10-08·CVSS 6.5
[MEDIUM] Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws
## Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws
## Lawrence Abrams
28 Elevation of Privilege vulnerabilities
7 Security Feature Bypass vulnerabilities
43 Remote Code Execution vulnerabilities
6 Information Disclosure vulnerabilities
26 Denial of Service vulnerabilities
7 Spoofing vulnerabilities
This count does not include three Edge flaws that were previously fixed on October 3rd.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5044284 and KB5044285 cumulative updates and the Windows 10 KB5044273 update .
## Five zero-days disclosed
This month's Patch Tuesday fixes five zero-days, two of which were actively exploited in attacks, and all five were publicly disclosed.
Microsoft classi
Trendmicro
The October 2024 Security Update Review
blogs_trendmicro·2024-10-08·CVSS 7.1
[HIGH] The October 2024 Security Update Review
## The October 2024 Security Update Review
Get the October 2024 security update and review.
By: Dustin Childs 2024/10/08 Read time: ( words)
Save to Folio
It’s the spooky season, and there’s nothing spookier than security patches – at least in my world. Microsoft and Adobe have released their latest patches, and no bones about it, there are some skeletons in those closets. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-43572
Microsoft Management Console Remote Code Execution Vulnerability
Moderate
7.8
Yes
Yes
RCE
CVE-2024-43573
Windows MSHTML Platform Spo
Trendmicro
The October 2024 Security Update Review
blogs_trendmicro·2024-10-08
The October 2024 Security Update Review
# The October 2024 Security Update Review
Get the October 2024 security update and review.
By: Dustin Childs
2024/10/08
Read time: ( words)
Save to Folio
It’s the spooky season, and there’s nothing spookier than security patches – at least in my world. Microsoft and Adobe have released their latest patches, and no bones about it, there are some skeletons in those closets. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for October 2024
For October, Adobe released nine patches addressing 52 CVEs in Adobe Substance 3D Painter, Commerce, Dimension, Animate, Lightroom, InCopy, InDesign, Substance 3D Stager, and A
Talos
Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilities
blogs_talos·2024-10-08·CVSS 7.8
[HIGH] Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilities
## Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilities
The largest Microsoft Patch Tuesday since July includes two vulnerabilities that have been exploited in the wild and three other critical issues across the company’s range of hardware and software offerings.
October’s monthly security update from Microsoft includes fixes for 117 CVEs, the most in a month since July’s updates covered 142 vulnerabilities .
The two vulnerabilities that Microsoft reports have been actively exploited in the wild and are publicly known are both rated as only being of “moderate” severity.
CVE-2024-43572 is a remote code execution vulnerability in the Microsoft Management Console that could allow an attacker to execute arbitrary code on the targeted machine.
Qualys
Microsoft and Adobe Patch Tuesday, October 2024 Security Update Review
blogs_qualys·2024-10-08
Microsoft and Adobe Patch Tuesday, October 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for October 2024
Adobe Patches for October 2024
Zero-day Vulnerabilities Patched in October Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in October Patch Tuesday Edition
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Microsoft has rolled out its October 2024 Patch Tuesday updates, offering vital security fixes for IT professionals to implement. With several critical vulnerabilities patched, this release highlights the ongoing need for regular maintenance and attention to security.
## Microsoft Patch Tuesday
Talos
Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilities
blogs_talos·2024-10-08·CVSS 9.8
[CRITICAL] Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilities
The largest Microsoft Patch Tuesday since July includes two vulnerabilities that have been exploited in the wild and three other critical issues across the company’s range of hardware and software offerings.
October’s monthly security update from Microsoft includes fixes for 117 CVEs, the most in a month since July’s updates covered 142 vulnerabilities.
The two vulnerabilities that Microsoft reports have been actively exploited in the wild and are publicly known are both rated as only being of “moderate” severity.
CVE-2024-43572 is a remote code execution vulnerability in the Microsoft Management Console that could allow an attacker to execute arbitrary code on the targeted machine. Microsoft’s security update will prevent untrusted Microsoft Saved Console (MSC) files from being opened
Crowdstrike
October 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] October 2024 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2024-10-08
Published