Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
CVE-2023-36867
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 11 July 2023
Summary
A vulnerability in the Visual Studio Code GitHub Pull Requests and Issues Extension allows attackers to execute arbitrary code on the user's system, potentially compromising the integrity of the development environment. This security flaw can be exploited if users install malicious code via the affected extension, leading to unauthorized access and data breaches. Users are strongly advised to monitor updates and apply security patches from Microsoft as necessary.
Affected Version(s)
Visual Studio Code - GitHub Pull Requests and Issues Extension Unknown 0.1.1 < 0.66.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved