Описание
Visual Studio Code Remote Code Execution Vulnerability
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An attacker could host a specially crafted web page and use social engineering to convince a user to have the application retrieve it. The malicious page could then cause the application to launch operating-system protocol handlers without prompting the user, which could result in code execution on the user's system. User interaction is required.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
8.8 High
CVSS3
Связанные уязвимости
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
EPSS
8.8 High
CVSS3