Skip to content
MicrosoftGHSA-5q6q-39p2-37cx

Remote Code Execution Vulnerability

HighCVE-2022-21991 · Published May 25, 2022 · updated May 30, 2022

A remote code execution vulnerability exists in VS Code 1.64.0 and earlier versions when debugging VS Code extensions remotely, for example using the Visual Studio Code Remote - SSH extension to connect to a machine and then develop a VS Code extension on that machine. When debugging VS Code extensions remotely, the remote extension host process would be launched in a way in which it would listen for debugger connections on all network interfaces. ### Patches The fix is available starting with **VS Code 1.64.1**. The fix (https://github.com/microsoft/vscode/commit/91f7694e68af5b5a9f05d920a5f0420dcb9c4ff5) mitigates this attack by launching the remote extension host in a way in which it listens for debugger connections only on the loopback interface when debugging VS Code extensions remotely. ### Workarounds There are no known workarounds for debugging VS Code extensions remotely. An alternative would be to develop and debug VS Code extensions locally. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/91f7694e68af5b5a9f05d920a5f0420dcb9c4ff5 * An issue for this can be found at https://github.com/microsoft/vscode/issues/142541 * MSRC ...

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.64.11.64.1
Details and references

A remote code execution vulnerability exists in VS Code 1.64.0 and earlier versions when debugging VS Code extensions remotely, for example using the Visual Studio Code Remote - SSH extension to connect to a machine and then develop a VS Code extension on that machine. When debugging VS Code extensions remotely, the remote extension host process would be launched in a way in which it would listen for debugger connections on all network interfaces. ### Patches The fix is available starting with **VS Code 1.64.1**. The fix (https://github.com/microsoft/vscode/commit/91f7694e68af5b5a9f05d920a5f0420dcb9c4ff5) mitigates this attack by launching the remote extension host in a way in which it listens for debugger connections only on the loopback interface when debugging VS Code extensions remotely. ### Workarounds There are no known workarounds for debugging VS Code extensions remotely. An alternative would be to develop and debug VS Code extensions locally. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/91f7694e68af5b5a9f05d920a5f0420dcb9c4ff5 * An issue for this can be found at https://github.com/microsoft/vscode/issues/142541 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21991

Severity from
GitHub (reviewed advisory)

More Microsoft advisories

All Microsoft
Advisory
Information Disclosure Vulnerability
MediumOct 11, 2022
Remote Code Execution Vulnerability
HighOct 11, 2022
Elevation of Privilege Vulnerability
HighSep 14, 2022
Spoofing Vulnerability
HighMay 25, 2022
Elevation of Privilege Vulnerability
HighMay 25, 2022
Remote Code Execution Vulnerability
HighMay 25, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.