Visual Studio Code Python Extension Remote Code Execution Vulnerability
CVE-2020-17163

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
29 December 2023

Summary

A remote code execution vulnerability exists in the Visual Studio Code Python Extension, allowing attackers to execute arbitrary code on the target system if the extension is installed. This vulnerability can be exploited through crafted commands, leading to potential unauthorized access and control over the affected environment. Users and organizations using this extension should ensure they have the latest updates to mitigate potential risks. For further details, please refer to the vendor advisory.

Affected Version(s)

Python extension for Visual Studio Code Unknown 2020

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.