Skip to content
MicrosoftGHSA-5cm6-54wm-6gg6

Remote Code Execution Vulnerability

HighCVE-2023-39956 · Published Sep 12, 2023

A remote code execution vulnerability exists in VS Code 1.80.1 and earlier versions where opening a maliciously crafted workspace from the command line `code <attacker-controlled-workspace>` can result in executing commands locally. Specifically this issue can only be exploited if the following conditions are met: * VS Code is launched with an attacker-controlled working directory * The attacker has the ability to write files to that working directory ### Patches The fix is available starting with VS Code 1.80.2. The fix (https://github.com/microsoft/vscode/commit/2ccd690cbff1569e4a83d7c43d45101f817401dc) mitigates the attack by updating to a newer version of Electron that contains the security fix. ### Workarounds There are no application side workarounds other than updating VS Code to the fixed version. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/2ccd690cbff1569e4a83d7c43d45101f817401dc * An issue for this can be found at https://github.com/microsoft/vscode/issues/192902 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-39956 * Electron's advisory can be found at https://gith...

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.80.21.80.2
Details and references

A remote code execution vulnerability exists in VS Code 1.80.1 and earlier versions where opening a maliciously crafted workspace from the command line `code <attacker-controlled-workspace>` can result in executing commands locally. Specifically this issue can only be exploited if the following conditions are met: * VS Code is launched with an attacker-controlled working directory * The attacker has the ability to write files to that working directory ### Patches The fix is available starting with VS Code 1.80.2. The fix (https://github.com/microsoft/vscode/commit/2ccd690cbff1569e4a83d7c43d45101f817401dc) mitigates the attack by updating to a newer version of Electron that contains the security fix. ### Workarounds There are no application side workarounds other than updating VS Code to the fixed version. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/2ccd690cbff1569e4a83d7c43d45101f817401dc * An issue for this can be found at https://github.com/microsoft/vscode/issues/192902 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-39956 * Electron's advisory can be found at https://github.com/advisories/GHSA-7x97-j373-85x5

Severity from
GitHub (reviewed advisory)

More Microsoft advisories

All Microsoft
Advisory
Elevation of Privilege Vulnerability
High8.8Mar 12, 2024
Remote Code Execution Vulnerability
HighSep 12, 2023
Information Disclosure Vulnerability
HighJun 13, 2023
Information Disclosure Vulnerability
HighMay 9, 2023
Remote Code Execution Vulnerability
HighApr 11, 2023
Remote Code Execution Vulnerability
MediumJan 10, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.