Skip to content
MicrosoftGHSA-f85p-3684-2g3j

Elevation of Privilege Vulnerability

MediumCVE-2025-24042 · Published Feb 11, 2025

## VS Code - Local escalation of priviledge vulnerability A vulnerability exists in VS Code 1.97.0 and earlier versions where an attacker with write permissions on certain common directories can place a binary that would be executed automatically by the JavaScript debugger. This requires an attacker to be able to create and modify files on the user's machine. ### Patches The fix is available starting with **VS Code 1.97.1**. The fix mitigates this by not resolving node_modules binaries outside of the workspace foler. ### Workarounds Specify absolute paths for the `runtimeExecutable` whenever you launch a program with the JavaScript debugger. ### References * The patch for this can be found at https://github.com/microsoft/vscode-js-debug/commit/51f431eaa3e8fe0e186e4e7e02664f5ae9aa1793 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24042

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.97.11.97.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Workspace trust for MCP servers
LowFeb 10
Security Feature Bypass Vulnerability
HighMay 13, 2025
Remote Code Execution Vulnerability
HighApr 8, 2025
Elevation of Privilege Vulnerability
HighFeb 11, 2025
Visual Studio Code for Linux Remote Code Execution Vulnerability
HighOct 8, 2024
Elevation of Privilege Vulnerability
High8.8Mar 12, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.