Visual Studio Code for Linux Remote Code Execution Vulnerability
HighCVE-2024-43601 · Published Oct 8, 2024
A remote code execution vulnerability exists in VS Code 1.94.0 and earlier versions in the elevated save flow. ### Patches The fix is available starting with **VS Code 1.94.1**. The fix (https://github.com/microsoft/vscode/commit/28000dfc8dd75bab443cf771cb1a7142219b4ae4) mitigates this attack by only allowing elevated save in trusted workspaces and hardening how arguments are passed around. ### Workarounds A way to avoid the vulnerability without updating is to not use the elevated save flow. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/28000dfc8dd75bab443cf771cb1a7142219b4ae4 * An issue for this can be found at https://github.com/microsoft/vscode/issues/230824 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43601
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode Product | < 1.94.1 | 1.94.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 132025 | Security Feature Bypass Vulnerability | High | 1.100.1 |
| Apr 82025 | Remote Code Execution Vulnerability | High | 1.99.1 |
| Feb 112025 | Elevation of Privilege Vulnerability | High | 1.97.1 |
| Feb 112025 | Elevation of Privilege Vulnerability | Medium | 1.97.1 |
| Mar 122024 | Elevation of Privilege Vulnerability | High8.8 | 1.87.2 |
| Sep 122023 | Remote Code Execution Vulnerability | High | 1.82.1 |