Visual Studio Code Jupyter Extension Spoofing Vulnerability
CVE-2023-36018
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 14 November 2023
Summary
The Visual Studio Code Jupyter Extension is susceptible to a spoofing vulnerability, allowing attackers to potentially manipulate the user interface. This can mislead users into believing they are interacting with legitimate content or prompts, leading to potential unauthorized actions. It is crucial for users of this extension to remain vigilant and stay updated with the latest security practices and patches provided by Microsoft to mitigate any risks associated with this issue.
Affected Version(s)
Jupyter Extension for Visual Studio Code Unknown 2022.0.0 < 2023.10.1100000000
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved