CVE-2018-0597: High severity visual studio code vulnerability
Published Jun 26, 2018
·Updated
Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
Microsoft Visual Studio Code
Event History
Jun 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0597?
CVE-2018-0597 is an untrusted search path vulnerability in the installer of Visual Studio Code.
2
What is the severity of CVE-2018-0597?
CVE-2018-0597 has a severity level of 7.8, which is considered high.
3
How can an attacker exploit CVE-2018-0597?
An attacker can exploit CVE-2018-0597 by using a Trojan horse DLL in an unspecified directory.
4
What is the affected software for CVE-2018-0597?
Microsoft Visual Studio Code is the affected software for CVE-2018-0597.
5
How can I fix CVE-2018-0597?
To fix CVE-2018-0597, it is recommended to update Visual Studio Code to the latest version available.