Microsoft Visual Studio Code vulnerabilities

52 known vulnerabilities affecting microsoft/visual_studio_code.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH43MEDIUM7

Vulnerabilities

Page 3 of 3
CVE-2021-27060HIGHCVSS 7.8≥ 1.0.0, < publication2021-03-11
CVE-2021-27060 [HIGH] CVE-2021-27060: Visual Studio Code Remote Code Execution Vulnerability Visual Studio Code Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-1639HIGHCVSS 7.8≥ 1.0.0, < publication2021-02-25
CVE-2021-1639 [HIGH] CVE-2021-1639: Visual Studio Code Remote Code Execution Vulnerability Visual Studio Code Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17148HIGHCVSS 7.8fixed in 0.61.02020-12-10
CVE-2020-17148 [HIGH] CVE-2020-17148: Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
nvd
CVE-2020-17104HIGHCVSS 7.8≥ 1.0.0, < publication2020-11-11
CVE-2020-17104 [HIGH] CVE-2020-17104: Visual Studio Code JSHint Extension Remote Code Execution Vulnerability Visual Studio Code JSHint Extension Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17023HIGHCVSS 7.8≥ 1.0.0, < publication2020-10-16
CVE-2020-17023 [HIGH] CVE-2020-17023: <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into op A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the aff
cvelistv5nvd
CVE-2020-16881HIGHCVSS 7.8fixed in 1.48.1≥ 1.0.0, < publication2020-09-11
CVE-2020-16881 [HIGH] CVE-2020-16881: <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into op A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the aff
cvelistv5nvd
CVE-2020-0604HIGHCVSS 8.8fixed in 0.24.0≥ 1.0.0, < publication2020-08-17
CVE-2020-0604 [HIGH] CVE-2020-0604: A remote code execution vulnerability exists in Visual Studio Code when it process environment varia A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected sy
cvelistv5nvd
CVE-2020-1416HIGHCVSS 8.8fixed in 1.47.1vunspecified2020-07-14
CVE-2020-1416 [HIGH] CWE-269 CVE-2020-1416: An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they loa An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
cvelistv5nvd
CVE-2020-1171HIGHCVSS 8.8vunspecified2020-05-21
CVE-2020-1171 [HIGH] CVE-2020-1171: A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads c A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1192.
cvelistv5nvd
CVE-2020-1192HIGHCVSS 8.8vunspecified2020-05-21
CVE-2020-1192 [HIGH] CVE-2020-1192: A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visua A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1171.
cvelistv5
CVE-2019-1414HIGHCVSS 7.8fixed in 1.39vunspecified2020-01-24
CVE-2019-1414 [HIGH] CVE-2019-1414: An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listene An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'.
cvelistv5nvd
CVE-2019-0728HIGHCVSS 7.8vunspecified2019-03-05
CVE-2019-0728 [HIGH] CVE-2019-0728: A remote code execution vulnerability exists in Visual Studio Code when it process environment varia A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.
cvelistv5nvd