Visual Studio Code Python Extension Remote Code Execution Vulnerability
CVE-2024-49050
8.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 November 2024
What is CVE-2024-49050?
The vulnerability in the Visual Studio Code Python Extension allows for remote code execution, which can be exploited by attackers to execute arbitrary code on the affected system without requiring user interaction. This flaw can potentially lead to significant security breaches, as malicious actors may utilize it to gain unauthorized access to sensitive data or control over systems running the extension. Users of Visual Studio Code are recommended to update their installations and Python extensions to the latest versions provided by Microsoft to mitigate the risk associated with this vulnerability.
Affected Version(s)
Python extension for Visual Studio Code Unknown 2020 < 2024.18.2