CVE-2024-49049: Visual Studio Code Remote Extension Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.1)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Nov
Released
2024-11-12
EPSS Score
0.34% (percentile: 57.0%)

FAQ

According to the CVSS metrics, the attack vector is local (AV:L) and privilege required is low (PR:L). What does that mean for this vulnerability? An attacker must have local access to the targeted machine and must be able to create folders and performance traces on the machine, with restricted privileges that normal users have by default.

Affected Products (1)

Developer Tools

  • Visual Studio Code Remote - SSH Extension

Security Updates (1)

Acknowledgments

Aleksandar Straumann with Meta, Greg Prosser with Meta

Revision History

  • 2024-11-12: Information published.