CVE-2024-49049
published 2024-11-12CVE-2024-49049: Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
PriorityP334high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.43%
34.6th percentile
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | remote_ssh | < 0.115.1 | 0.115.1 |
| microsoft | visual_studio_code_remote_ssh_extension | >= 1.0.0 < 0.115.1 | 0.115.1 |
| msrc | visual_studio_code_remote_ssh_extension | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
vendor_msrc·2024-11-12·CVSS 7.1
CVE-2024-49049 [HIGH] CWE-284 Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
FAQ: According to the CVSS metrics, the attack vector is local (AV:L) and privilege required is low (PR:L). What does that mean for this vulnerability?
An attacker must have local access to the targeted machine and must be able to create folders and performance traces on the machine, with restricted privileges that normal users have by default.
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://marketplace.visualstudio.com/items?itemName=ms-vscode-remote.remote-ssh
Reference: https://github.com/mi
GHSA
GHSA-9gw8-gc35-hprv: Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-11-12
CVE-2024-49049 [HIGH] CWE-284 GHSA-9gw8-gc35-hprv: Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
2024-11-12
Published