cbcvebase.
CVE-2024-43488
published 2024-10-08

CVE-2024-43488: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution…

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.15%
63.2th percentile
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.

Affected

2 ranges
VendorProductVersion rangeFixed in
microsoftvisual_studio_code
msrcvisual_studio_code

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-43488 affects the Visual Studio Code extension for Arduino; the extension has been deprecated and removed from the VS Code marketplace as of October 1, 2024. Detect presence of the extension in environments as a risk indicator.
  • The vulnerability is exploitable via a network-based attack vector requiring no authentication; monitor for unexpected network connections originating from or targeting the VS Code Arduino extension process.
  • The flaw stems from missing authentication for critical functions within the Arduino extension; alert on unauthenticated remote function calls to the extension's network-exposed interface.
  • ·Microsoft has fully mitigated this vulnerability server-side (cloud service CVE); no patch is available or planned since the extension is deprecated. Exploitation status is 'Less Likely' with no public exploit or active exploitation confirmed.
  • ·The extension will not receive a fix; Microsoft recommends migrating to Arduino IDE software instead of the VS Code extension.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.