CVE-2022-21991HighCVSS 8.1
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
How could an attacker exploit this vulnerability? An attacker would need to send a specially crafted request to a host running the Visual Studio Code Remote Development Extension. This issue only affects systems configured to host a remote development environment.
🎯 Affected products1
- Visual Studio Code
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.64.1