First published: Tue Apr 13 2021(Updated: )
Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio Code | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28448 is rated as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2021-28448, update Visual Studio Code Kubernetes Tools to version 1.3.0 or later.
CVE-2021-28448 can allow an attacker to execute arbitrary code on systems using vulnerable versions of the Kubernetes Tools extension.
CVE-2021-28448 affects any operating system running vulnerable versions of Visual Studio Code Kubernetes Tools.
You can check your version of Kubernetes Tools in Visual Studio Code and confirm it is below 1.3.0 to determine vulnerability to CVE-2021-28448.