Visual Studio Code Python Extension Remote Code Execution Vulnerability
CVE-2024-49050

8.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 November 2024

Summary

The vulnerability in the Visual Studio Code Python Extension allows for remote code execution, which can be exploited by attackers to execute arbitrary code on the affected system without requiring user interaction. This flaw can potentially lead to significant security breaches, as malicious actors may utilize it to gain unauthorized access to sensitive data or control over systems running the extension. Users of Visual Studio Code are recommended to update their installations and Python extensions to the latest versions provided by Microsoft to mitigate the risk associated with this vulnerability.

Affected Version(s)

Python extension for Visual Studio Code Unknown 2020 < 2024.18.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.