Skip to content
MicrosoftGHSA-g56j-w527-8x6f

Visual Studio Code for Linux Remote Code Execution Vulnerability

HighCVE-2024-43601 · Published Oct 8, 2024

A remote code execution vulnerability exists in VS Code 1.94.0 and earlier versions in the elevated save flow. ### Patches The fix is available starting with **VS Code 1.94.1**. The fix (https://github.com/microsoft/vscode/commit/28000dfc8dd75bab443cf771cb1a7142219b4ae4) mitigates this attack by only allowing elevated save in trusted workspaces and hardening how arguments are passed around. ### Workarounds A way to avoid the vulnerability without updating is to not use the elevated save flow. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/28000dfc8dd75bab443cf771cb1a7142219b4ae4 * An issue for this can be found at https://github.com/microsoft/vscode/issues/230824 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43601

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.94.11.94.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Security Feature Bypass Vulnerability
HighMay 13, 2025
Remote Code Execution Vulnerability
HighApr 8, 2025
Elevation of Privilege Vulnerability
HighFeb 11, 2025
Elevation of Privilege Vulnerability
MediumFeb 11, 2025
Elevation of Privilege Vulnerability
High8.8Mar 12, 2024
Remote Code Execution Vulnerability
HighSep 12, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.