2017 Visual Studio Code Workspace...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

The following issue constitutes an arbitrary code execution vulnerability in Visual Studio Code (herein referred to as "Code"). Users should upgrade to Code 1.9.0 or later. <https://en.wikipedia.org/wiki/Visual_Studio_Code> says: > Visual Studio Code is a source code editor developed by Microsoft for > Windows, Linux and macOS. It includes support for debugging, embedded Git > control, syntax highlighting, intelligent code completion, snippets, and code > refactoring. It is also customizable, so users can change the editor's theme, > keyboard shortcuts, and preferences. It is free and open-source, although the > official download is under a proprietary license. The vulnerability can be exploited in the event that a user loads a directory in Code, where that directory contains specially-crafted contents. In Code parlance, a directory represents a "Workspace". This could arise in the following scenarios: * Where an attacker controls a world-readable directory on a multi-user system...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息