Elevation of Privilege Vulnerability
HighCVE-2025-24039 · Published Feb 11, 2025
## VS Code - Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists in VS Code 1.97.0 and earlier versions for users of the `code serve-web` command on Windows. An attacker can place an evil version of the node module that is optionally required by one of the dependencies for the Visual Studio Code remote server in a world writable directory like `C:\node_modules` to get it executed under the privileges of the current user. ## Patches The fix is available starting with **VS Code 1.97.1**. The fix (https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332) mitigates this attack by removing common world writable directories from the node module dependency resolution logic. ## Workarounds There are no known workarounds at this time. Do not run `code serve-web` as an elevated user on a machine where untrusted users can write to the world writable directories. ## References - The patch for this can be found at https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332 - An issue for this can be found at https://github.com/microsoft/vscode/issues/240406 - MSRC details for this can be found at https://m...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode Product | < 1.97.1 | 1.97.1 |
Details and references
## VS Code - Elevation of Privilege Vulnerability An elevation of privilege vulnerability exists in VS Code 1.97.0 and earlier versions for users of the `code serve-web` command on Windows. An attacker can place an evil version of the node module that is optionally required by one of the dependencies for the Visual Studio Code remote server in a world writable directory like `C:\node_modules` to get it executed under the privileges of the current user. ## Patches The fix is available starting with **VS Code 1.97.1**. The fix (https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332) mitigates this attack by removing common world writable directories from the node module dependency resolution logic. ## Workarounds There are no known workarounds at this time. Do not run `code serve-web` as an elevated user on a machine where untrusted users can write to the world writable directories. ## References - The patch for this can be found at https://github.com/microsoft/vscode/commit/ebd0778eec319f51b84269e2a8291d612e851332 - An issue for this can be found at https://github.com/microsoft/vscode/issues/240406 - MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24039
- Severity from
- GitHub (reviewed advisory)
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 10 | Workspace trust for MCP servers | Low | 1.109.1 |
| May 132025 | Security Feature Bypass Vulnerability | High | 1.100.1 |
| Apr 82025 | Remote Code Execution Vulnerability | High | 1.99.1 |
| Feb 112025 | Elevation of Privilege Vulnerability | Medium | 1.97.1 |
| Oct 82024 | Visual Studio Code for Linux Remote Code Execution Vulnerability | High | 1.94.1 |
| Mar 122024 | Elevation of Privilege Vulnerability | High8.8 | 1.87.2 |