Skip to content
MicrosoftGHSA-6c5x-m47q-5xmf

Elevation of Privilege Vulnerability

HighCVE-2022-38020 · Published Sep 14, 2022

An elevation of privilege vulnerability exists in VS Code v1.71.0 and earlier versions where on a shared Windows machine, a low-privileged user can create a `bash.exe` executable in a location where terminal profiles are detected. This detected profile is then exposed in the terminal profiles list and can be run easily by a higher-privileged user on the same machine. The paths in question were: * `C:\Cygwin64\bin\bash.exe` * `C:\Cygwin\bin\bash.exe` * `C:\ProgramData\scoop\apps\git-with-openssh\current\bin\bash.exe` ### Patches The fix is available starting with **VS Code 1.71.1**. The fix (https://github.com/microsoft/vscode/commit/0b356bf51acf15749e0e22d28fb803d7171e975e) mitigates this attack by removing those paths completely from the terminal profile detection feature. ### Workarounds Avoid running terminal profiles that are not expected to be installed on the machine. An administrator may be able to lock down the folders in question. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/0b356bf51acf15749e0e22d28fb803d7171e975e * An issue for this can be found at https://github.com/microsoft/vscode/issues/160827 * MSRC details for...

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.71.11.71.1
Details and references

An elevation of privilege vulnerability exists in VS Code v1.71.0 and earlier versions where on a shared Windows machine, a low-privileged user can create a `bash.exe` executable in a location where terminal profiles are detected. This detected profile is then exposed in the terminal profiles list and can be run easily by a higher-privileged user on the same machine. The paths in question were: * `C:\Cygwin64\bin\bash.exe` * `C:\Cygwin\bin\bash.exe` * `C:\ProgramData\scoop\apps\git-with-openssh\current\bin\bash.exe` ### Patches The fix is available starting with **VS Code 1.71.1**. The fix (https://github.com/microsoft/vscode/commit/0b356bf51acf15749e0e22d28fb803d7171e975e) mitigates this attack by removing those paths completely from the terminal profile detection feature. ### Workarounds Avoid running terminal profiles that are not expected to be installed on the machine. An administrator may be able to lock down the folders in question. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/0b356bf51acf15749e0e22d28fb803d7171e975e * An issue for this can be found at https://github.com/microsoft/vscode/issues/160827 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38020

Severity from
GitHub (reviewed advisory)

More Microsoft advisories

All Microsoft
Advisory
Information Disclosure Vulnerability
MediumOct 11, 2022
Remote Code Execution Vulnerability
HighOct 11, 2022
Remote Code Execution Vulnerability
HighMay 25, 2022
Spoofing Vulnerability
HighMay 25, 2022
Elevation of Privilege Vulnerability
HighMay 25, 2022
Remote Code Execution Vulnerability
HighMay 25, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.