Описание
Visual Studio Code Elevation of Privilege Vulnerability
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This means that a successful attack is not limited to Visual Studio Code itself, but can also affect the user’s local system, including files and settings. As a result, the impact extends beyond the application to a different security boundary, increasing the overall severity of the vulnerability.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have be enticed to open a malicious .code-workspace file in vscode. Users should never open anything that they do not know or trust to be safe.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
9.6 Critical
CVSS3
Связанные уязвимости
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Уязвимость редактора исходного кода Microsoft Visual Studio Code, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии
EPSS
9.6 Critical
CVSS3