Skip to content
MicrosoftGHSA-532g-4pv9-25f2

Elevation of Privilege Vulnerability

HighCVE-2025-24039 · Published Feb 11, 2025

## VS Code - Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists in VS Code 1.97.0 and earlier versions for users of the `code serve-web` command on Windows. An attacker can place an evil version of the node module that is optionally required by one of the dependencies for the Visual Studio Code remote server in a world writable directory like `C:\node_modules` to get it executed under the privileges of the current user. ## Patches The fix is available starting with **VS Code 1.97.1**. The fix (https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332) mitigates this attack by removing common world writable directories from the node module dependency resolution logic. ## Workarounds There are no known workarounds at this time. Do not run `code serve-web` as an elevated user on a machine where untrusted users can write to the world writable directories. ## References - The patch for this can be found at https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332 - An issue for this can be found at https://github.com/microsoft/vscode/issues/240406 - MSRC details for this can be found at https://m...

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.97.11.97.1
Details and references

## VS Code - Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists in VS Code 1.97.0 and earlier versions for users of the `code serve-web` command on Windows. An attacker can place an evil version of the node module that is optionally required by one of the dependencies for the Visual Studio Code remote server in a world writable directory like `C:\node_modules` to get it executed under the privileges of the current user. ## Patches The fix is available starting with **VS Code 1.97.1**. The fix (https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332) mitigates this attack by removing common world writable directories from the node module dependency resolution logic. ## Workarounds There are no known workarounds at this time. Do not run `code serve-web` as an elevated user on a machine where untrusted users can write to the world writable directories. ## References - The patch for this can be found at https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332 - An issue for this can be found at https://github.com/microsoft/vscode/issues/240406 - MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24039

Severity from
GitHub (reviewed advisory)

More Microsoft advisories

All Microsoft
Advisory
Workspace trust for MCP servers
LowFeb 10
Security Feature Bypass Vulnerability
HighMay 13, 2025
Remote Code Execution Vulnerability
HighApr 8, 2025
Elevation of Privilege Vulnerability
MediumFeb 11, 2025
Visual Studio Code for Linux Remote Code Execution Vulnerability
HighOct 8, 2024
Elevation of Privilege Vulnerability
High8.8Mar 12, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.