CVE-2021-28967: Critical severity visual studio code vulnerability
Published Mar 24, 2021
·Updated
The unofficial MATLAB extension before 2.0.1 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace because of lint configuration settings.
Affected Software
2 affected components
Microsoft Visual Studio Code Matlab<2.0.1
Gimly Matlab Visual Studio Code<2.0.1
Remediation
Event History
Mar 24, 2021
CVE Published
via MITRE·06:19 AM
Data Sourced
via MITRE·06:19 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-28967?
CVE-2021-28967 is an unofficial MATLAB extension vulnerability in Visual Studio Code that allows attackers to execute arbitrary code via a crafted workspace.
2
What is the severity of CVE-2021-28967?
The severity of CVE-2021-28967 is critical with a CVSS score of 9.8.
3
How can attackers exploit CVE-2021-28967?
Attackers can exploit CVE-2021-28967 by using a crafted workspace with malicious lint configuration settings.
4
What software is affected by CVE-2021-28967?
The unofficial MATLAB extension before version 2.0.1 for Microsoft Visual Studio Code is affected by CVE-2021-28967.
5
How do I fix CVE-2021-28967?
To fix CVE-2021-28967, update the unofficial MATLAB extension for Visual Studio Code to version 2.0.1 or later.