First published: Tue Mar 16 2021(Updated: )
Visual Studio Code Python Extension Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Python Extension for Visual Studio Code | <2020.9.2 | |
Visual Studio Code |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17163 has a severity rating of critical due to its potential for remote code execution.
To fix CVE-2020-17163, update the Microsoft Python Extension for Visual Studio Code to version 2020.9.2 or later.
Exploitation of CVE-2020-17163 could allow an attacker to execute arbitrary code on a system running the vulnerable Python extension.
CVE-2020-17163 affects all versions of the Python extension for Visual Studio Code prior to 2020.9.2.
You can check your version of the Microsoft Python Extension in Visual Studio Code to determine if it is below version 2020.9.2, which indicates vulnerability.