Описание
Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have be enticed to open a malicious file in vscode. Users should never open anything that they do not know or trust to be safe.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Visual Studio Code - MSSQL Extension |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.8 High
CVSS3
Связанные уязвимости
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Уязвимость расширения для работы с базами данных MSSQL Extension редактора исходного кода Visual Studio Code, позволяющая нарушителю повысить свои привилегии или выполнить произвольный код
EPSS
7.8 High
CVSS3