CVE-2024-49049: Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.1)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2024-Nov
- Released
- 2024-11-12
- EPSS Score
- 0.34% (percentile: 57.0%)
FAQ
According to the CVSS metrics, the attack vector is local (AV:L) and privilege required is low (PR:L). What does that mean for this vulnerability?
An attacker must have local access to the targeted machine and must be able to create folders and performance traces on the machine, with restricted privileges that normal users have by default.
Affected Products (1)
Developer Tools
- Visual Studio Code Remote - SSH Extension
Security Updates (1)
Acknowledgments
Aleksandar Straumann with Meta, Greg Prosser with Meta
Revision History
- 2024-11-12: Information published.