CVE-2022-21991: Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
Published Feb 8, 2022
·Updated
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft Visual Studio Code
Microsoft Visual Studio Code
Event History
Feb 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Feb 9, 2022
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-21991?
CVE-2022-21991 is a vulnerability in the Visual Studio Code Remote Development Extension that allows remote code execution.
2
How does CVE-2022-21991 affect Microsoft Visual Studio Code?
CVE-2022-21991 affects Microsoft Visual Studio Code by allowing remote code execution through the Remote Development Extension.
3
What is the severity of CVE-2022-21991?
CVE-2022-21991 has a severity rating of 8.1 (high).
4
How can I fix CVE-2022-21991?
To fix CVE-2022-21991, it is recommended to update to the latest version of Visual Studio Code and ensure that the Remote Development Extension is also up to date.
5
Where can I find more information about CVE-2022-21991?
For more information about CVE-2022-21991, you can refer to the official Microsoft Security Response Center (MSRC) website.