First published: Tue Mar 05 2019(Updated: )
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio Code |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0728 is a remote code execution vulnerability in Visual Studio Code.
CVE-2019-0728 occurs when Visual Studio Code processes environment variables after opening a project.
The severity of CVE-2019-0728 is critical (7.8).
Microsoft Visual Studio Code is affected by CVE-2019-0728.
To fix CVE-2019-0728, it is recommended to apply the latest security updates provided by Microsoft.