Visual Studio Code Python Extension Remote Code Execution Vulnerability
CVE-2020-17163
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 29 December 2023
Summary
A remote code execution vulnerability exists in the Visual Studio Code Python Extension, allowing attackers to execute arbitrary code on the target system if the extension is installed. This vulnerability can be exploited through crafted commands, leading to potential unauthorized access and control over the affected environment. Users and organizations using this extension should ensure they have the latest updates to mitigate potential risks. For further details, please refer to the vendor advisory.
Affected Version(s)
Python extension for Visual Studio Code Unknown 2020
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved