Msrc Visual Studio Code vulnerabilities
49 known vulnerabilities affecting msrc/visual_studio_code.
Total CVEs
49
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH41MEDIUM7
Vulnerabilities
Page 2 of 3
CVE-2022-30129HIGHCVSS 8.82022-05-10
CVE-2022-30129 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:
msrc
CVE-2022-26921HIGHCVSS 7.32022-04-12
CVE-2022-26921 [HIGH] Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
Reference: h
msrc
CVE-2022-24526MEDIUMCVSS 6.12022-03-08
CVE-2022-24526 [MEDIUM] Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have be enticed to open a malicious file in vscode. Users should never open anything that they do not know or trust to be safe.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would
msrc
CVE-2022-21991HIGHCVSS 8.12022-02-08
CVE-2022-21991 [HIGH] Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
FAQ: How could an attacker exploit this vulnera
msrc
CVE-2021-43891HIGHCVSS 7.82021-12-14
CVE-2021-43891 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-43908MEDIUMCVSS 4.32021-12-14
CVE-2021-43908 [MEDIUM] Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-42322HIGHCVSS 7.82021-11-09
CVE-2021-42322 [HIGH] Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
Reference: h
msrc
CVE-2021-26437MEDIUMCVSS 5.52021-09-14
CVE-2021-26437 [MEDIUM] Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
Visual Studio: Visual Studio
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-34529HIGHCVSS 7.82021-07-13
CVE-2021-34529 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
FAQ: How does Visual Studio Code protect against remote code execution vulnerabilities in extensions?
With the release of Visual Studio Code 1.57, a new feature was added called Workspace Trust. This new feature allows developers to open unfamiliar code or extensions in Restricted Mode with the option to later mark the code as trusted. Restricted Mode works to prev
msrc
CVE-2021-34479HIGHCVSS 7.82021-07-13
CVE-2021-34479 [HIGH] Microsoft Visual Studio Spoofing Vulnerability
Microsoft Visual Studio Spoofing Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-34528HIGHCVSS 7.82021-07-13
CVE-2021-34528 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-31214HIGHCVSS 7.82021-05-11
CVE-2021-31214 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have be enticed to open a malicious file in a directory. Users should never open anything that they do not know or trust to be safe.
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit S
msrc
CVE-2021-31211HIGHCVSS 7.82021-05-11
CVE-2021-31211 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have be enticed to open a malicious file in a directory. Users should never open anything that they do not know or trust to be safe.
FAQ: How do I know if I am affected by this vulnerability?
Customers running any Visual Studio Code Re
msrc
CVE-2021-28457HIGHCVSS 7.82021-04-13
CVE-2021-28457 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-28475HIGHCVSS 7.82021-04-13
CVE-2021-28475 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-28473HIGHCVSS 7.82021-04-13
CVE-2021-28473 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-28477HIGHCVSS 7.02021-04-13
CVE-2021-28477 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-28469HIGHCVSS 7.82021-04-13
CVE-2021-28469 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc
CVE-2021-28471HIGHCVSS 7.82021-04-13
CVE-2021-28471 [HIGH] Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code
msrc
CVE-2021-27060HIGHCVSS 7.82021-03-09
CVE-2021-27060 [HIGH] Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code: Visual Studio Code
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://code.visualstudio.com/Download
msrc