CVE-2022-21991HighCVSS 8.1

Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability

Published
February 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.

How could an attacker exploit this vulnerability? An attacker would need to send a specially crafted request to a host running the Visual Studio Code Remote Development Extension. This issue only affects systems configured to host a remote development environment.

🎯 Affected products1

  • Visual Studio Code

✅ Remediation

KBRelease Notes (Security Update) — fixed build 1.64.1

🔗 References (2)